Job Summary for Splunk Detection and Incident Response Dashboard Engineer
- Design, build, and maintain Splunk dashboards to support Security Operations Center (SOC) incident detection, investigation, and response workflows.
- Develop visualizations and dashboards for key security metrics, including incident volume/severity, Mean Time to Detect (MTTD), Mean Time to Respond/Resolve (MTTR), and alert fidelity/false positive trends.
- Build and optimize Splunk searches, reports, and panels to surface suspicious activity, detections, and notable security events.
- Collaborate closely with Detection Engineers, Incident Responders, and SOC Analysts to understand use cases, threats, and investigation requirements.
- Ensure dashboards are aligned with SOC workflows, enabling analysts to efficiently transition from visualizations to investigations.
- Enhance dashboard performance and usability by refining searches and optimizing data models for security analytics.
- Document dashboard logic, metric definitions, and assumptions to ensure clarity and consistency in operations.
- Leverage experience with security data sources such as authentication logs, endpoint telemetry, network logs, and application security logs.
- Transform unstructured security data into actionable visual insights for SOC operations.
- Apply strong analytical skills and attention to detail to ensure accuracy and effectiveness of dashboards and reports.