remote
Senior Splunk Engineer - RBC
Software Engineer
Senior Splunk Engineer leading the design, implementation, and tuning of a global SIEM platform, building data pipelines, and developing detection rules to enhance cyber resiliency using Splunk, Python, and cloud services.
About the role
Key Responsibilities
- Design, deploy, and maintain the enterprise Splunk SIEM platform and associated data pipeline infrastructure.
- Develop, tune, and optimize detection rules, dashboards, and alerts to meet evolving cyber threat requirements.
- Integrate diverse data sources via REST APIs, syslog, and cloud services (e.g., AWS) into the SIEM environment.
- Collaborate with security analysts, incident responders, and engineering teams to translate security use cases into actionable Splunk content.
- Automate repetitive tasks and enrich data using Python scripts and Linux tooling.
- Provide technical mentorship, documentation, and best‑practice guidance for the SIEM ecosystem.
Requirements
- 5+ years of hands‑on experience with Splunk Enterprise and Splunk Cloud deployments.
- Strong background in SIEM architecture, log collection, and security analytics.
- Proficiency in Python scripting and Linux system administration.
- Experience integrating data sources via REST APIs and working with cloud platforms such as AWS.
- Demonstrated ability to create and fine‑tune detection rules, dashboards, and alerts in a high‑volume security environment.
Skills
splunkpythonlinuxaws