Cyber Analyst- Level 3
Indexed description
We are looking for a candidate who lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts.
Responsibilities
- Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources.
- Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
- Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
- Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches.
- Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility.
- Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
- Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
- Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
- Create documentation, runbooks, and detection specifications to support downstream analysts.
- Have a current "L" , "Q" or "TS" clearance.
- Have the following required skillsets:
- Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization.
- Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework.
- Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections.
- Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment.
- Strong understanding of the MITRE ATT&CK framework and detection engineering methodology.
- Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.).
- Experience with detection-as-code practices and tools (Git, CI/CD pipelines).
- Proficiency in Python for data processing and model development.
- Knowledge of SOAR platforms and detection automation.
- Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.).
- Prior experience in a SOC, threat hunting, or incident response role.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search