Jobgether

Security Platform Engineer

Jobgether United States · $96K–$125K/yr

Internet Marketplace Platforms · 11-50 employees

19 h ago
Remote Senior (5-10 yrs) Contractor United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Design, implement, and maintain enterprise-scale Splunk and Cribl environments while building reliable security data pipelines. Collaborate with SOC analysts and infrastructure teams to optimize detection use cases, security automation, and platform performance.

What they look for

Splunk Enterprise Splunk Enterprise Security Cribl Stream Security Operations Center Data pipelines Log management Detection engineering Security automation SPL Python PowerShell Bash Linux administration REST APIs JSON Cloud security

Requirements

Requires 5+ years of hands-on experience with Splunk Enterprise, including administration and security monitoring. Proficiency in log onboarding, data modeling, scripting, and familiarity with security automation platforms is essential.

Benefits

Medical insurance Dental insurance Vision insurance Major holiday benefits Paid sick leave Remote work opportunity

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Platform Engineer based in United States.

This role offers the opportunity to engineer and operate enterprise-scale security platforms supporting modern Security Operations Center environments. You will focus on Splunk Enterprise, Splunk Enterprise Security, and Cribl Stream while helping build reliable security data pipelines and monitoring capabilities. The position combines platform engineering, log management, detection engineering, troubleshooting, and security automation. You will work closely with SOC analysts, security engineers, architects, and infrastructure teams to improve visibility and operational efficiency. Your work will directly contribute to scalable security monitoring, data quality, and automated response capabilities. This is a strong opportunity for an experienced security engineer who enjoys solving complex platform challenges in a highly technical environment.

\n

Accountabilities

  • Design, implement, administer, and maintain Splunk Enterprise and Splunk Enterprise Security environments at enterprise scale.
  • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
  • Develop and maintain data onboarding pipelines from security, infrastructure, cloud, and enterprise technology sources.
  • Configure and troubleshoot log ingestion, parsing, field extraction, normalization, Common Information Model (CIM) mapping, and data models.
  • Optimize Splunk searches, dashboards, reports, correlation searches, and other monitoring content for performance and scalability.
  • Build and maintain detection use cases, alerts, and security monitoring capabilities.
  • Develop security automation workflows using platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar technologies.
  • Integrate security and enterprise tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, AWS, Azure, and related technologies.
  • Troubleshoot ingestion failures, parsing issues, search performance problems, and distributed platform architecture challenges.
  • Implement platform monitoring, health checks, capacity planning, upgrades, and operational best practices.
  • Collaborate with SOC analysts, security engineers, architects, and infrastructure teams to support security operations.
  • Create and maintain technical documentation, standard operating procedures, and operational runbooks.

Requirements

  • 5+ years of hands-on experience working with Splunk Enterprise, with strong expertise in enterprise administration and support.
  • Strong experience with Splunk Enterprise Security and security monitoring environments.
  • Hands-on experience administering Cribl Stream and developing data processing pipelines.
  • Strong understanding of log onboarding, parsing, field extraction, normalization, CIM, and data modeling.
  • Proficiency with Splunk Search Processing Language (SPL).
  • Experience working with Splunk index management, forwarders, deployment servers, search heads, indexers, and clustered environments.
  • Experience integrating cloud platforms and security products with Splunk.
  • Knowledge of Linux administration and troubleshooting.
  • Experience working with REST APIs and JSON.
  • Scripting experience using Python, PowerShell, Bash, or similar technologies.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq is preferred.
  • Familiarity with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP is advantageous.
  • Knowledge of the MITRE ATT&CK framework and familiarity with security operations and incident response workflows.
  • Experience with Git, CI/CD, and Infrastructure as Code is a plus.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl certifications, CISSP, or GIAC certifications are advantageous.
  • Experience designing enterprise SIEM architectures, developing threat detection capabilities, or implementing SOC automation is highly valued.
  • Strong communication and collaboration skills with the ability to work effectively across technical and security teams.

Benefits

  • Competitive compensation of $46–$60 per hour, with the starting rate dependent on qualifications, experience, and location.
  • W2 employment structure.
  • Option to elect healthcare benefits, including medical, dental, and vision insurance.
  • Major holiday benefits.
  • Paid sick leave in accordance with applicable state law.
  • Opportunity to work with enterprise-scale security platforms and modern SIEM technologies.
  • Exposure to security automation, cloud security, threat detection, and SOC operations.
  • Opportunity to develop expertise across Splunk, Cribl, SOAR platforms, and leading security technologies.
  • Remote work opportunity.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1