Role: Security Platform Engineer
Location: Remote
In USA
Mandatory: Splunk, Cribl
Preferred: Automation
Job Summary
We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.
Key Responsibilities
- Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
- Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
- Develop and maintain data onboarding pipelines from various security and infrastructure sources.
- Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
- Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
- Build and maintain detection use cases, alerts, and security monitoring content.
- Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
- Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
- Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
- Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
- Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
- Create technical documentation, SOPs, and operational runbooks.
Required Skills
- 5+ years of hands-on experience with Splunk Enterprise.
- Strong experience administering and supporting Splunk Enterprise Security (ES).
- Hands-on experience with Cribl Stream administration and pipeline development.
- Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
- Experience with Splunk Search Processing Language (SPL).
- Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
- Experience integrating cloud and security products with Splunk.
- Knowledge of Linux administration and troubleshooting.
- Experience with REST APIs and JSON.
- Scripting experience using Python, PowerShell, or Bash.
- Strong troubleshooting and analytical skills.
Preferred Skills
- Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
- Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.
- Knowledge of MITRE ATT&CK framework.
- Familiarity with security operations and incident response workflows.
- Experience with Git, CI/CD, and Infrastructure as Code.
- Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.
Nice to Have
- Experience designing enterprise SIEM architectures.
- Experience with threat detection engineering.
- Experience implementing SOC automation and orchestration workflows.
- Exposure to cloud-native security monitoring and observability platforms.