Contract W2 Only || Security Platform Engineer (SOC, Splunk, Cribl) || Remote

Noblesoft Technologies

  • raleigh, NC
  • 2 days ago
  • Remote

    Highlights

    Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.

    Numbers & Facts

    Locationraleigh, NC (
    Remote
    )

    Description

    Role: Security Platform Engineer
    Location: Remote

    In USA

    Mandatory: Splunk, Cribl

    Preferred: Automation

    Job Summary

    We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.

    Key Responsibilities

    • Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
    • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
    • Develop and maintain data onboarding pipelines from various security and infrastructure sources.
    • Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
    • Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
    • Build and maintain detection use cases, alerts, and security monitoring content.
    • Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
    • Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
    • Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
    • Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
    • Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
    • Create technical documentation, SOPs, and operational runbooks.

    Required Skills

    • 5+ years of hands-on experience with Splunk Enterprise.
    • Strong experience administering and supporting Splunk Enterprise Security (ES).
    • Hands-on experience with Cribl Stream administration and pipeline development.
    • Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
    • Experience with Splunk Search Processing Language (SPL).
    • Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
    • Experience integrating cloud and security products with Splunk.
    • Knowledge of Linux administration and troubleshooting.
    • Experience with REST APIs and JSON.
    • Scripting experience using Python, PowerShell, or Bash.
    • Strong troubleshooting and analytical skills.

    Preferred Skills

    • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
    • Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.
    • Knowledge of MITRE ATT&CK framework.
    • Familiarity with security operations and incident response workflows.
    • Experience with Git, CI/CD, and Infrastructure as Code.
    • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.

    Nice to Have

    • Experience designing enterprise SIEM architectures.
    • Experience with threat detection engineering.
    • Experience implementing SOC automation and orchestration workflows.
    • Exposure to cloud-native security monitoring and observability platforms.

    Similar Jobs

    See more jobs