companyIT Security C&T logo

Senior Splunk Engineer at IT Security C&T | Amman

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Senior

Qualifications

Required Skills & Experience:A minimum of 5 years of hands-on experience in SIEM engineering, with at least 3 years dedicated to Splunk Enterprise or Splunk Cloud. Expertise in SPL (Search Processing Language), data onboarding, and CIM normalization. Experience in integrating various log sources, including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intelligence feeds. Strong grasp of security operations, detection engineering, and incident response processes. Familiarity with Splunk ES, UBA, ITSI, and SOAR is preferred but not mandatory. Proficiency in scripting and automation using Python, Bash, and PowerShell. Solid understanding of networking, security protocols, and system administration (Windows/Linux). Awareness of regulatory and compliance frameworks such as ISO 27001, NCA, SAMA, PCI-DSS, etc.

About the job

  • Job Summary:

    As a Senior Splunk Engineer, you will play a pivotal role in the design, execution, management, and enhancement of Splunk Enterprise or Splunk Cloud in a large-scale corporate or managed services framework. You will oversee log onboarding, develop correlation rules, create dashboards, and tune performance to ensure the Splunk platform provides precise, actionable insights for security operations and compliance monitoring.

    Key Responsibilities:

  • Architect and deploy comprehensive Splunk solutions encompassing data ingestion, parsing, indexing, and search optimization.
  • Design and sustain custom correlation rules, alerts, dashboards, and visualizations to bolster security monitoring and incident response.
  • Integrate new log sources from infrastructure, security, applications, and cloud systems using best practices (e.g., UF, HF, syslog, APIs).
  • Conduct routine health assessments, performance tuning of indexers and search heads, monitor license usage, and secure configuration backups.
  • Support threat detection efforts by converting security use cases into actionable Splunk queries and alerts.
  • Assist in resolving ingestion failures, parsing issues, and inefficient search queries.
  • Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, integrity, and quality.
  • Oversee Splunk Enterprise Security (ES) configurations, ensuring CIM compliance, managing notables, and implementing risk-based alerting (RBA).
  • Establish and manage data retention policies and storage optimization aligned with compliance mandates.
  • Automate processes using scripting languages (Python, Bash, PowerShell) and configuration management tools as necessary.
  • Provide technical mentorship and guidance to junior Splunk engineers and analysts.

About IT Security C&T

IT Security C&T is a dynamic and rapidly expanding security consulting and training firm. Our management team, along with our expert consultants and engineers, collaborates to deliver comprehensive security solutions to clients across the MENA region. We are committed to continually growing our team of skilled professionals, offering a multitude of opportunities. Interested candidates are encouraged to apply through our Career webpage at www.itsecurityct.com.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.