
Splunk SME | Lead Splunk | Splunk Consultant | Splunk Engineer
We are seeking an experienced Senior Splunk Subject Matter Expert with a strong background in automation development and expertise in Splunk SOAR (Security Orchestration, Automation, and Response). As a Senior SME, you will work closely with our customers onsite to gain insights into their existing security operations, identify automation opportunities, design efficient automation workflows, and deploy them utilizing Splunk SOAR. This is an exciting opportunity for an individual passionate about improving security operations through automation while helping customers maximize the value of Splunk SOAR.
Key Responsibilities
- Customer Engagement & Insights
- Work directly with customers to understand their security operations and identify areas where automation can streamline processes, reduce response times, and increase overall operational efficiency.
- Conduct workshops, requirements gathering sessions, and technical discussions to understand the customer s environment, pain points, and goals.
- Translate business requirements into effective automation use cases, focusing on improving security operations and incident management.
- Automation Design & Development
- Design and develop automation workflows using Splunk SOAR to address identified use cases and streamline security response processes.
- Leverage Splunk SOAR s playbooks, triggers, and integrations to develop customized automation solutions that meet client requirements.
- Work with existing Splunk infrastructure, Splunk ITSI (IT Service Intelligence), and other relevant technologies to implement integrated solutions that optimize security operations.
- Implementation & Deployment
- Oversee the deployment and configuration of Splunk SOAR on client environments, ensuring alignment with their security policies and operational requirements.
- Provide hands-on support during the deployment phase, ensuring a smooth transition and integration of automation workflows.
- Troubleshoot, optimize, and fine-tune deployed automation solutions to ensure optimal performance.
- Training & Knowledge Transfer
- Provide training and mentoring to customer teams on best practices for Splunk SOAR operations, automation design, and workflow management.
- Assist customers in building self-sufficiency by providing knowledge transfer on automation, incident management, and Splunk SOAR features.
- Continuous Improvement
- Continuously improve automation strategies by staying up-to-date with the latest trends, features, and updates within Splunk SOAR and the broader security automation field.
- Assess the impact of automation workflows, gather feedback, and refine existing solutions to improve performance and customer satisfaction.
- Collaboration & Communication
- Collaborate with cross-functional teams, including security analysts, engineers, and other SMEs, to deliver integrated automation solutions.
- Maintain clear and effective communication with all stakeholders, ensuring transparency and alignment of project goals, timelines, and deliverables.
Required Skills & Experience
- Splunk SOAR Expertise
- Hands-on experience with Splunk SOAR (formerly Phantom), including playbook creation, automation design, and integration.
- Proficient in developing and maintaining custom Splunk SOAR integrations (connectors, APIs, and custom scripts) to extend functionality.
- In-depth understanding of security operations workflows and use cases in the context of incident response, threat intelligence, and security automation.
- Automation Development
- Strong proficiency in Python for writing scripts to automate tasks and enhance security operations.
- Experience in RESTful APIs, JSON, XML, and other automation-related technologies.
- Familiarity with Version Control systems such as Git for code management.
- Security Operations & Incident Response
- Extensive experience in security operations centers (SOC) or similar environments, particularly in incident response, monitoring, and automated workflows.
- Strong knowledge of security tools and frameworks such as SIEM, SOAR, and EDR systems, especially within the context of automated threat detection and response.
- Client-Facing Skills
- Ability to work directly with clients, understand their needs, and translate them into actionable automation solutions.
- Strong communication, presentation, and interpersonal skills, with the ability to explain complex technical concepts to non-technical stakeholders.
- Problem-Solving & Analytical Skills
- Excellent troubleshooting and diagnostic skills, especially in complex, multi-layered security environments.
- Ability to analyze business processes and identify areas where automation will create the most value.
Preferred Skills
- Experience with Splunk ITSI and other Splunk solutions for security monitoring and reporting.
- Familiarity with cloud environments (AWS, Azure, Google Cloud Platform) and their integration with security automation tools.
- Understanding of DevOps practices and CI/CD pipeline integration with security automation.
Certifications
The following certifications are required to be considered for this role:
- Splunk SOAR Certification (Splunk Phantom Certified Administrator or Developer)
- Splunk Enterprise Certified Admin (Preferred)
- Splunk Enterprise Security (ES) Certified Admin (Preferred)
- Certified Information Systems Security Professional (CISSP) (Preferred)
- Certified Ethical Hacker (CEH) or similar security certifications (Preferred)
- Python Programming Certification (Preferred)
- AWS Certified Security Specialty or equivalent cloud security certifications (Preferred)
Education & Experience
- Bachelor s Degree in Computer Science, Information Security, or related field, or equivalent work experience.
- 10+ years of experience in information security, with at least 5+ years of hands-on experience specifically with Splunk SOAR and automation development.
- Proven track record of working with enterprise clients to implement security automation solutions and improve operational efficiency.
We are seeking an experienced Senior Splunk Subject Matter Expert with a strong background in automation development and expertise in Splunk SOAR (Security Orchestration, Automation, and Response). As a Senior SME, you will work closely with our customers onsite to gain insights into their existing security operations, identify automation opportunities, design efficient automation workflows, and deploy them utilizing Splunk SOAR. This is an exciting opportunity for an individual passionate about improving security operations through automation while helping customers maximize the value of Splunk SOAR.
Key Responsibilities
- Customer Engagement & Insights
- Work directly with customers to understand their security operations and identify areas where automation can streamline processes, reduce response times, and increase overall operational efficiency.
- Conduct workshops, requirements gathering sessions, and technical discussions to understand the customer s environment, pain points, and goals.
- Translate business requirements into effective automation use cases, focusing on improving security operations and incident management.
- Automation Design & Development
- Design and develop automation workflows using Splunk SOAR to address identified use cases and streamline security response processes.
- Leverage Splunk SOAR s playbooks, triggers, and integrations to develop customized automation solutions that meet client requirements.
- Work with existing Splunk infrastructure, Splunk ITSI (IT Service Intelligence), and other relevant technologies to implement integrated solutions that optimize security operations.
- Implementation & Deployment
- Oversee the deployment and configuration of Splunk SOAR on client environments, ensuring alignment with their security policies and operational requirements.
- Provide hands-on support during the deployment phase, ensuring a smooth transition and integration of automation workflows.
- Troubleshoot, optimize, and fine-tune deployed automation solutions to ensure optimal performance.
- Training & Knowledge Transfer
- Provide training and mentoring to customer teams on best practices for Splunk SOAR operations, automation design, and workflow management.
- Assist customers in building self-sufficiency by providing knowledge transfer on automation, incident management, and Splunk SOAR features.
- Continuous Improvement
- Continuously improve automation strategies by staying up-to-date with the latest trends, features, and updates within Splunk SOAR and the broader security automation field.
- Assess the impact of automation workflows, gather feedback, and refine existing solutions to improve performance and customer satisfaction.
- Collaboration & Communication
- Collaborate with cross-functional teams, including security analysts, engineers, and other SMEs, to deliver integrated automation solutions.
- Maintain clear and effective communication with all stakeholders, ensuring transparency and alignment of project goals, timelines, and deliverables.
Required Skills & Experience
- Splunk SOAR Expertise
- Hands-on experience with Splunk SOAR (formerly Phantom), including playbook creation, automation design, and integration.
- Proficient in developing and maintaining custom Splunk SOAR integrations (connectors, APIs, and custom scripts) to extend functionality.
- In-depth understanding of security operations workflows and use cases in the context of incident response, threat intelligence, and security automation.
- Automation Development
- Strong proficiency in Python for writing scripts to automate tasks and enhance security operations.
- Experience in RESTful APIs, JSON, XML, and other automation-related technologies.
- Familiarity with Version Control systems such as Git for code management.
- Security Operations & Incident Response
- Extensive experience in security operations centers (SOC) or similar environments, particularly in incident response, monitoring, and automated workflows.
- Strong knowledge of security tools and frameworks such as SIEM, SOAR, and EDR systems, especially within the context of automated threat detection and response.
- Client-Facing Skills
- Ability to work directly with clients, understand their needs, and translate them into actionable automation solutions.
- Strong communication, presentation, and interpersonal skills, with the ability to explain complex technical concepts to non-technical stakeholders.
- Problem-Solving & Analytical Skills
- Excellent troubleshooting and diagnostic skills, especially in complex, multi-layered security environments.
- Ability to analyze business processes and identify areas where automation will create the most value.
Preferred Skills
- Experience with Splunk ITSI and other Splunk solutions for security monitoring and reporting.
- Familiarity with cloud environments (AWS, Azure, Google Cloud Platform) and their integration with security automation tools.
- Understanding of DevOps practices and CI/CD pipeline integration with security automation.
Certifications
The following certifications are required to be considered for this role:
- Splunk SOAR Certification (Splunk Phantom Certified Administrator or Developer)
- Splunk Enterprise Certified Admin (Preferred)
- Splunk Enterprise Security (ES) Certified Admin (Preferred)
- Certified Information Systems Security Professional (CISSP) (Preferred)
- Certified Ethical Hacker (CEH) or similar security certifications (Preferred)
- Python Programming Certification (Preferred)
- AWS Certified Security Specialty or equivalent cloud security certifications (Preferred)
Education & Experience
- Bachelor s Degree in Computer Science, Information Security, or related field, or equivalent work experience.
- 10+ years of experience in information security, with at least 5+ years of hands-on experience specifically with Splunk SOAR and automation development.
- Proven track record of working with enterprise clients to implement security automation solutions and improve operational efficiency.