Splunk Enterprise Security Expert

YOCHANA IT SOLUTIONS, INC.
  • CA
    3 days ago

    Job Description

    Knowledge Object Governance & Lifecycle Management

    • Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections.
    • Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types - ensuring consistent, parseable, and discoverable naming across teams, apps, and deployments.
    • Conduct regular audits of knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting objects - retiring obsolete content and consolidating redundant objects across teams and deployments.
    • Create custom automations to track the ingest of data, the consistent flow of the data, drift of data away from the normalization standards, etc.
    • Define and maintain a knowledge object registry/catalog that documents ownership, scope, purpose, permissions, and lifecycle stage for each object in the environment.
    • Collaborate enterprise Splunk platform teams on permission structures and sharing models - ensuring objects are accessible to the correct roles (read/write/execute) across apps, environments, and user tiers without overexposure.
    • Lead the promotion pipeline for knowledge objects from development through testing, staging, and production - establishing change control workflows aligned to CI/CD and GitOps practices (GitHub, GitHub Actions).

    CIM Normalization & Data Model management

    • Serve as the CIM (Common Information Model) authority for the enterprise - defining and maintaining CIM-compliant field mappings across all ingested data sources including endpoints (EDR/AV), network (firewall, proxy, DNS), identity (IAM, AD), cloud (AWS CloudTrail, Azure Monitor, GCP Logging), and application layers.
    • Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting - ensuring alignment to CIM schemas and ES asset/identity frameworks.
    • Manage data model acceleration strategies (TSIDX, tstats, summary indexing) across all production data models, monitoring for search load, acceleration lag, and coverage gaps.
    • Define and enforce source-type and index taxonomy standards - establishing lexicographic naming conventions that optimize search performance, configuration priority, and multi-team usability.
    • Ensure entity zone enrichment (asset zones, network zones, identity tiers) is properly incorporated into data models and asset/identity lookups, supporting tiered risk scoring in Enterprise Security.
    • Maintain CIM coverage matrices across all logging domains, mapping data model fields to MITRE ATT&CK techniques, detection use cases, and compliance controls.

    Knowledge Architecture & Standards Program

    • Design and own the enterprise Splunk knowledge architecture - defining taxonomy hierarchies, content type standards, metadata schemas, and classification frameworks that enable findability, scalability, and governance across all teams.
    • Develop and maintain a Knowledge Management Standards document (published to internal wiki/SharePoint) covering naming conventions, object lifecycle stages, ownership models, permission templates, CIM mapping standards, and change control procedures.
    • Establish and chair a Knowledge Governance Working Group composed of representatives from Detection Engineering, SOC Operations, Platform Engineering, Compliance, and key application teams - meeting regularly to review standards, resolve conflicts, and prioritize improvements.
    • Define content type templates for correlation searches, dashboards, reports, lookups, and macros - providing reusable, pre-approved scaffolding that accelerates new content development while enforcing standards compliance.

    Required Technical Skills & Technologies

    Splunk Core

    • Splunk Enterprise (distributed, multi-site, clustered) deep administrative and engineering proficiency
    • Splunk Enterprise Security (ES) correlation searches, notable events, risk rules, threat intelligence, asset/identity frameworks
    • Splunk Common Information Model (CIM) - advanced normalization across all major data model domains
    • SPL (Search Processing Language) - advanced query authoring including tstats, macros, sub-searches, eval functions, streaming/non-streaming commands
    • Data Models - design, acceleration management (TSIDX), Pivot support, ES data model dependencies
    • Knowledge Objects - full lifecycle mastery: field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, saved searches, correlation searches
    • Splunk Apps & Add-ons - TA development/review, app packaging, deployment via Deployment Server and Deployer
    • Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules)
    • Splunk Edge Processor / Ingest Processor - pipeline-level routing and data transformation awareness

    Platform & Infrastructure

    • Multi-cloud environments: AWS, Azure, GCP - log source integration, cloud-native telemetry normalization
    • Linux and Windows system administration
    • Python and Bash/Shell scripting - automation of knowledge object management, API-driven content deployment
    • GitHub / GitHub Actions / CI-CD pipelines - knowledge object version control, automated testing, promotion workflows

    Frameworks & Standards

    • MITRE ATT&CK - technique mapping for detection content governance
    • NIST CSF / 800-53, CIS Benchmarks - compliance-driven knowledge requirements
    • Agile / Scrum methodology for iterative content development

    Required Qualifications

    • Bachelor's degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
    • 8+ years of hands-on Splunk experience in enterprise environments
    • 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
    • Deep expertise in Splunk Enterprise Security - correlation search authoring, ES data models, risk-based alerting
    • Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
    • Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
    • Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
    • Proven ability to create and maintain technical documentation - runbooks, standards guides, architecture documentation
    • Background in detection engineering, threat hunting, or SOC operations - understanding of how knowledge objects serve analysts in practice

    Preferred Qualifications

    • Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect - one or more strongly preferred
    • Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
    • Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
    • Familiarity with Splunk UBA and behavioral analytics model management
    • Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
    • Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
    • Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
    • Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention

    Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing

    Numbers & Facts

    LocationCA

    Skills

    • Agile Programming Methodologiesunmatched
    • Amazon Web Services (AWS)unmatched
    • Ansibleunmatched
    • Application Programming Interface (API)unmatched
    • Artificial Intelligence (AI)unmatched
    • Audiovisualunmatched
    • Auditingunmatched
    • Automationunmatched
    • Bash Scriptingunmatched
    • Benchmarkingunmatched
    • CIM (Common Information Model)unmatched
    • Change Controlunmatched
    • Cloud Computingunmatched
    • Computer Scienceunmatched
    • Configuration Managementunmatched
    • Consultingunmatched
    • Content Developmentunmatched
    • Content Managementunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • DNS (Domain Name System)unmatched
    • Data Managementunmatched
    • Data Mappingunmatched
    • Data Modelingunmatched
    • Documentationunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • File Managementunmatched
    • Firewallsunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GCP (Good Clinical Practices)unmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • GitHubunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Healthcareunmatched
    • Huntingunmatched
    • Information Retrievalunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Knowledge Managementunmatched
    • Linux Administrationunmatched
    • Machine Toolunmatched
    • Maintain Complianceunmatched
    • Metadataunmatched
    • Microsoft SharePointunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows System Administrationunmatched
    • Object Modelingunmatched
    • PCIunmatched
    • Performance Tuning/Optimizationunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulatory Complianceunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Modelingunmatched
    • Scaffoldingunmatched
    • Scripting (Scripting Languages)unmatched
    • Scrum Project Management and Software Developmentunmatched
    • Search Engine Optimization (SEO)unmatched
    • Security Information and Event Management (SIEM)unmatched
    • Splunkunmatched
    • Taxonomiesunmatched
    • Technical Writingunmatched
    • Telemetryunmatched
    • Test Plan/Scheduleunmatched
    • Theater Productionunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Unix Shell Programmingunmatched
    • Usability Engineeringunmatched
    • Use Casesunmatched
    • Wikiunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder