About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Splunk Enterprise Security Expert based in Brazil.
This role offers the opportunity to shape enterprise-wide Splunk governance and security content architecture at significant scale.
Responsibilities
- Provide centralized governance and lifecycle management for Splunk knowledge objects, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV Store collections.
- Establish and enforce enterprise-wide naming conventions, taxonomy standards, ownership models, permissions, and lifecycle processes for Splunk content.
- Audit knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting content and drive consolidation or retirement where appropriate.
- Develop automation to monitor data ingestion, data flow consistency, normalization drift, and other critical aspects of the Splunk environment.
- Maintain an enterprise knowledge object registry documenting ownership, scope, purpose, permissions, and lifecycle stage.
- Collaborate with platform teams to define appropriate permission structures and sharing models across applications, environments, and user groups.
- Lead the promotion of knowledge objects through development, testing, staging, and production using change control, CI/CD, and GitOps practices.
- Serve as the enterprise authority for Splunk Common Information Model (CIM) normalization and maintain compliant field mappings across endpoint, network, identity, cloud, and application data sources.
- Design, build, and maintain Splunk data models supporting Pivot users, Enterprise Security correlation searches, reporting, and risk-based analytics.
- Manage data model acceleration strategies, including TSIDX, tstats, and summary indexing, while monitoring search load, acceleration performance, and coverage.
- Define and enforce source-type and index taxonomy standards to improve search performance, configuration consistency, and usability across teams.
- Ensure asset zones, network zones, identity tiers, and other entity enrichment are incorporated into data models and Enterprise Security frameworks.
- Maintain CIM coverage matrices connecting data model fields with MITRE ATT&CK techniques, detection use cases, and compliance controls.
- Own the enterprise Splunk knowledge architecture, including taxonomy hierarchies, content standards, metadata schemas, and classification frameworks.
- Develop and maintain knowledge management standards covering naming conventions, lifecycle stages, ownership, permissions, CIM mappings, and change control procedures.
- Lead a cross-functional knowledge governance working group involving detection engineering, SOC operations, platform engineering, compliance, and application teams.
- Create reusable templates for correlation searches, dashboards, reports, lookups, and macros to accelerate development while maintaining governance standards.
- Design and implement automation using Python, Bash, GitHub Actions, and related tooling to improve knowledge object management and deployment.
- Maintain clear technical documentation, including architecture documentation, standards guides, runbooks, and operational procedures.
- Support detection engineering, threat hunting, and SOC teams by ensuring Splunk content is reliable, discoverable, performant, and aligned with operational needs.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
- 8+ years of hands-on Splunk experience in enterprise environments.
- At least 3 years of direct experience in Splunk knowledge management, CIM normalization, SIEM content engineering, or comparable large-scale Splunk environments.
- Experience working with large-scale Splunk deployments, ideally handling 20+ TB of data per day.
- Deep expertise in Splunk Enterprise Security, including correlation searches, notable events, risk-based alerting, ES data models, threat intelligence, and asset and identity frameworks.
- Advanced proficiency in SPL, including complex statistical pipelines, tstats, macros, sub-searches, evaluation functions, and streaming and non-streaming commands.
- Strong understanding of Splunk data models, acceleration strategies, Pivot functionality, and Enterprise Security dependencies.
- Comprehensive knowledge of Splunk knowledge objects and their full lifecycle, including field extractions, lookups, KV Store collections, macros, tags, aliases, event types, workflow actions, saved searches, and correlation searches.
- Deep administrative and engineering experience with distributed, multi-site, and clustered Splunk Enterprise environments.
- Experience developing or reviewing Splunk Technology Add-ons and applications, including packaging and deployment through Deployment Server and Deployer.
- Strong understanding of Splunk configuration and deployment best practices.