Sr Splunk Detection Engineer

Cherokee Federal · via Himalayas ·

Budget / Salary$150,000–160,000
TypeFull-time job
LocationUnited States
Posted4 hours ago
Senior Splunk Detection Engineer
Criterion Systems, a Cherokee Federal company, is seeking a Senior Splunk Detection Engineer to support the National Science Foundation (NSF) Cybersecurity & Privacy Program.
This hands-on Detection Engineering role is responsible for improving Security Operations Center (SOC) effectiveness through high-fidelity detections, Risk-Based Alerting (RBA), alert tuning, incident response collaboration, and future security automation initiatives. The successful candidate will partner closely with Security Operations, Incident Response, Cloud Engineering, and Vulnerability Management teams to build scalable detection capabilities that reduce false positives, improve analyst efficiency, and strengthen NSF's cybersecurity posture.
Compensation & Benefits
Estimated Starting Salary Range for Senior Splunk Detection Engineer:$150,000–$160,000
Pay commensurate with experience.
Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.
Senior Splunk Detection Engineer Responsibilities Include

Design, build, test, and continuously improve Splunk Enterprise Security detection content.

Develop and tune correlation searches, notable events, adaptive response actions, dashboards, and investigation workflows.

Implement and optimize Risk-Based Alerting (RBA) strategies.

Improve detection quality while reducing false positives and minimizing false negatives.

Map detections to the MITRE ATT&CK Framework and maintain coverage metrics.

Partner with Incident Response teams to convert real-world incidents into improved detection content.

Participate in threat hunting, incident investigations, tabletop exercises, and purple team activities.

Develop cloud detections leveraging AWS GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs, and related telemetry.

Maintain Common Information Model (CIM) compliance and improve data normalization.

Measure detection quality through precision, recall, MTTR, and analyst workload reduction.

Support future Splunk SOAR (Phantom) automation initiatives.

Integrate Splunk Enterprise Security with ServiceNow Incident Response and other security technologies.

Collaborate with Security Operations, Cloud Engineering, Vulnerability Management, and Incident Response teams.

Performs other job-related duties as assigned.

Senior Splunk Detection Engineer Experience, Education, Skills, Abilities Requested

Active Public Trust clearance or the ability to obtain one.

Minimum seven (7) years of cybersecurity experience, including four (4) years in Detection Engineering, Security Operations, Incident Response, or Splunk Enterprise Security.

Experience building and tuning Splunk Enterprise Security correlation searches.

Hands-on Risk-Based Alerting (RBA) implementation experience.

Practical Incident Response experience or close partnership with IR teams.

Strong understanding of MITRE ATT&CK.

Experience improving detection fidelity and reducing false positives.

Strong AWS security knowledge including GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, and VPC Flow Logs.

Proficiency with SPL, Python, REST APIs, and Git.

Experience developing Splunk dashboards, reports, and investigations.

Excellent written and verbal communication skills.

Preferred:
Splunk Enterprise Security certifications

Splunk SOAR (Phantom)

Detection-as-Code

Sigma and YARA

CrowdStrike or Microsoft Defender for Endpoint

ServiceNow Incident Response

Knowledge of FISMA, NIST RMF, FedRAMP, and CMMC

Must pass pre-employment qualifications of Cherokee Federal.

Company Information
Criterion Systems, a Cherokee Federal company, provides innovative cybersecurity, cloud, digital transformation, and IT solutions supporting federal government customers. As part of Cherokee Federal, Criterion Systems delivers mission-focused technology services while providing employees with opportunities for professional growth and meaningful impact.
#CherokeeFederal # AppC
Cherokee Federal is a military-friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.
Similar Searchable Job Titles

Senior Detection Engineer

Splunk Detection Engineer

Splunk Enterprise Security Engineer

Cyber Detection Engineer

Security Operations Engineer

SIEM Engineer

Threat Detection Engineer

SOC Detection Engineer

Cybersecurity Engineer

Security Analytics Engineer

Keywords

Splunk Enterprise Security

Splunk ES

Detection Engineering

Risk-Based Alerting

RBA

SIEM

MITRE ATT&CK

Incident Response

Threat Hunting

AWS Security

GuardDuty

CloudTrail

Security Hub

Python

SPL

SOAR

Phantom

ServiceNow

Sigma

YARA

CrowdStrike

Microsoft Defender

FedRAMP

NIST RMF

FISMA

CMMC

Public Trust

Legal Disclaimer
Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, accommodation requests, and other employment notices. Many positions require access to government facilities or military installations.
Originally posted on Himalayas
detection-engineering splunk-detection-engineer security-operations-engineer cybersecurity-engineer siem-engineer senior-threat-hunting-engineer senior-threat-detection-engineering-manager senior-threat-detection-analyst threat-detection-engineer detection-and-response-engineer detection-engineer
Apply on Himalayas →

Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.