Jobs · Engineering

Security Platform Engineer

Danta Technologies · United States · 2 wk ago
RemoteRemoteEngineeringContract

About the Role

We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will design, implement, optimize, and support enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.

Responsibilities

  • Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
  • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
  • Develop and maintain data onboarding pipelines from various security and infrastructure sources.
  • Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
  • Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
  • Build and maintain detection use cases, alerts, and security monitoring content.
  • Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
  • Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
  • Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
  • Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
  • Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
  • Create technical documentation, SOPs, and operational runbooks.

Requirements

  • 5+ years of hands-on experience with Splunk Enterprise.
  • Strong experience administering and supporting Splunk Enterprise Security (ES).
  • Hands-on experience with Cribl Stream administration and pipeline development.
  • Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
  • Experience with Splunk Search Processing Language (SPL).
  • Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
  • Experience integrating cloud and security products with Splunk.
  • Knowledge of Linux administration and troubleshooting.
  • Experience with REST APIs and JSON.
  • Scripting experience using Python, PowerShell, or Bash.
  • Strong troubleshooting and analytical skills.

Preferred Qualifications

  • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.
  • Knowledge of MITRE ATT&CK framework.
  • Familiarity with security operations and incident response workflows.
  • Experience with Git, CI/CD, and Infrastructure as Code.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.
  • Experience designing enterprise SIEM architectures.
  • Experience with threat detection engineering.
  • Experience implementing SOC automation and orchestration workflows.
  • Exposure to cloud-native security monitoring and observability platforms.

Benefits

  • Competitive pay.
  • Option to elect healthcare insurance (Dental, Medical, Vision).
  • Major holidays and paid sick leave as per state law.

The rate/salary range is dependent on numerous factors including qualifications, experience, and location.

Similar jobs