SIEM Engineer – Splunk & Splunk Cloud
On-siteAdelaide, South Australia, Australia or Melbourne, Victoria, Australia
Job Summary
Engineer and support Splunk Enterprise and Splunk Cloud environments by managing indexers, search heads, forwarders, apps, and add-ons. Onboard and troubleshoot security log sources while developing and tuning SPL searches, alerts, and dashboards. Support SOC teams with detection and investigation requirements, troubleshoot ingestion and platform performance issues, and integrate Microsoft 365, Azure, AWS, EDR, and identity data. Work with customers, vendors, and internal teams to maintain technical documentation and procedures. Participate in an on-call roster, typically 1–2 weeks per month.
Required Qualifications
- Strong Splunk Enterprise and/or Splunk Cloud experience
- Strong SPL and SIEM knowledge
- Experience with Splunk CIM, apps/add-ons and forwarders
- Experience onboarding security logs across multiple platforms
- Understanding of SIEM, SOC operations and threat detection
- Experience with syslog, APIs, JSON, XML and regular expressions
- Strong troubleshooting skills across Linux, Windows and cloud
- Strong communication and stakeholder management skills
- Ability to obtain an Australian Government Security Clearance
Desired Qualifications
- Experience Google SecOps and YARA-L
- Microsoft Sentinel and KQL
- Sumo Logic / Cloud SIEM
- Microsoft Defender, Azure Security or AWS Security
- Palo Alto, CrowdStrike or SOAR platforms
- Automation, scripting, Git or Infrastructure as Code
- Splunk, Microsoft or cybersecurity certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.