Cherokee Federal Logo

Cherokee Federal

Sr Splunk Detection Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
150K-160K Annually
Senior level
Remote
Hiring Remotely in United States
150K-160K Annually
Senior level
Designs and improves Splunk Enterprise Security detections, correlation searches, dashboards, investigations, and Risk-Based Alerting strategies. Tunes alerts to reduce false positives, maps coverage to MITRE ATT&CK, and partners with incident response, threat hunting, cloud engineering, and vulnerability management teams. Develops AWS security detections using GuardDuty and related telemetry, maintains CIM compliance, measures detection effectiveness, and supports future Splunk SOAR automation and ServiceNow integrations.
The summary above was generated by AI

Senior Splunk Detection Engineer

Criterion Systems, a Cherokee Federal company, is seeking a Senior Splunk Detection Engineer to support the National Science Foundation (NSF) Cybersecurity & Privacy Program.

This hands-on Detection Engineering role is responsible for improving Security Operations Center (SOC) effectiveness through high-fidelity detections, Risk-Based Alerting (RBA), alert tuning, incident response collaboration, and future security automation initiatives. The successful candidate will partner closely with Security Operations, Incident Response, Cloud Engineering, and Vulnerability Management teams to build scalable detection capabilities that reduce false positives, improve analyst efficiency, and strengthen NSF's cybersecurity posture.

Compensation & Benefits

Estimated Starting Salary Range for Senior Splunk Detection Engineer: $150,000–$160,000

Pay commensurate with experience.

Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.

Senior Splunk Detection Engineer Responsibilities Include

  • Design, build, test, and continuously improve Splunk Enterprise Security detection content.
  • Develop and tune correlation searches, notable events, adaptive response actions, dashboards, and investigation workflows.
  • Implement and optimize Risk-Based Alerting (RBA) strategies.
  • Improve detection quality while reducing false positives and minimizing false negatives.
  • Map detections to the MITRE ATT&CK Framework and maintain coverage metrics.
  • Partner with Incident Response teams to convert real-world incidents into improved detection content.
  • Participate in threat hunting, incident investigations, tabletop exercises, and purple team activities.
  • Develop cloud detections leveraging AWS GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs, and related telemetry.
  • Maintain Common Information Model (CIM) compliance and improve data normalization.
  • Measure detection quality through precision, recall, MTTR, and analyst workload reduction.
  • Support future Splunk SOAR (Phantom) automation initiatives.
  • Integrate Splunk Enterprise Security with ServiceNow Incident Response and other security technologies.
  • Collaborate with Security Operations, Cloud Engineering, Vulnerability Management, and Incident Response teams.
  • Performs other job-related duties as assigned.

Senior Splunk Detection Engineer Experience, Education, Skills, Abilities Requested

  • Active Public Trust clearance or the ability to obtain one.
  • Minimum seven (7) years of cybersecurity experience, including four (4) years in Detection Engineering, Security Operations, Incident Response, or Splunk Enterprise Security.
  • Experience building and tuning Splunk Enterprise Security correlation searches.
  • Hands-on Risk-Based Alerting (RBA) implementation experience.
  • Practical Incident Response experience or close partnership with IR teams.
  • Strong understanding of MITRE ATT&CK.
  • Experience improving detection fidelity and reducing false positives.
  • Strong AWS security knowledge including GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, and VPC Flow Logs.
  • Proficiency with SPL, Python, REST APIs, and Git.
  • Experience developing Splunk dashboards, reports, and investigations.
  • Excellent written and verbal communication skills.
  • Preferred:
    • Splunk Enterprise Security certifications
    • Splunk SOAR (Phantom)
    • Detection-as-Code
    • Sigma and YARA
    • CrowdStrike or Microsoft Defender for Endpoint
    • ServiceNow Incident Response
    • Knowledge of FISMA, NIST RMF, FedRAMP, and CMMC
  • Must pass pre-employment qualifications of Cherokee Federal.

Company Information

Criterion Systems, a Cherokee Federal company, provides innovative cybersecurity, cloud, digital transformation, and IT solutions supporting federal government customers. As part of Cherokee Federal, Criterion Systems delivers mission-focused technology services while providing employees with opportunities for professional growth and meaningful impact.

#CherokeeFederal # AppC #LI-SM2

Cherokee Federal is a military-friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

Similar Searchable Job Titles

  • Senior Detection Engineer
  • Splunk Detection Engineer
  • Splunk Enterprise Security Engineer
  • Cyber Detection Engineer
  • Security Operations Engineer
  • SIEM Engineer
  • Threat Detection Engineer
  • SOC Detection Engineer
  • Cybersecurity Engineer
  • Security Analytics Engineer

Keywords

  • Splunk Enterprise Security
  • Splunk ES
  • Detection Engineering
  • Risk-Based Alerting
  • RBA
  • SIEM
  • MITRE ATT&CK
  • Incident Response
  • Threat Hunting
  • AWS Security
  • GuardDuty
  • CloudTrail
  • Security Hub
  • Python
  • SPL
  • SOAR
  • Phantom
  • ServiceNow
  • Sigma
  • YARA
  • CrowdStrike
  • Microsoft Defender
  • FedRAMP
  • NIST RMF
  • FISMA
  • CMMC
  • Public Trust

Legal Disclaimer

Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, accommodation requests, and other employment notices. Many positions require access to government facilities or military installations.

Similar Jobs

11 Days Ago
Remote
United States
148K-185K Annually
Senior level
148K-185K Annually
Senior level
Healthtech • Database
The Senior Detection Engineer will manage SIEM platforms like Splunk, support compliance frameworks, and integrate security platforms across environments.
Top Skills: AWSCrowdstrike FalconEdrSIEMSplunk Enterprise Security
An Hour Ago
Remote or Hybrid
United States
75K-110K Annually
Mid level
75K-110K Annually
Mid level
Cloud • Fintech • Software • Financial Services
Own go-to-market strategy and execution for YCharts data products, partnering with Product, Marketing, Sales, and Customer Success. Responsibilities include launch planning, product positioning, messaging, sales enablement, customer and competitive research, internal and external communications, and coordinating multiple concurrent launches. The role translates complex financial products and market data into clear customer value for wealth managers, advisors, and asset managers.
An Hour Ago
Remote or Hybrid
Jersey City, NJ, USA
125K-169K Annually
Senior level
125K-169K Annually
Senior level
Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
Build and maintain sales operations infrastructure for the Marketplace commercial team, including dashboards, forecasting, pipeline management, CRM administration, data quality, onboarding workflows, process automation, and business reporting. Partner with Finance, Analytics, Product, Account Management, and leadership to improve operating cadence, performance measurement, and growth insights in a fast-moving marketplace environment.
Top Skills: CRMData WarehouseGoogle SheetsLightdashLookerExcelSQLTableau

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account