[Remote] Splunk Engineer (RBA) (R-00101) at True Zero Technologies

Hundred, West Virginia, United States

True Zero Technologies Logo
Not SpecifiedCompensation
Mid-level (3 to 4 years), Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, TechnologyIndustries

Requirements

  • Deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL)
  • Strong understanding of security operations, threat detection, incident response, and security frameworks (e.g., NIST RMF)
  • Relevant Splunk certifications such as: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect
  • Proficiency in scripting languages like Python, PowerShell, or Bash for automation and data analysis
  • Willingness to collaborate within an agile environment

Responsibilities

  • Implement RBA: Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts
  • Develop RBA components: Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores
  • Create dashboards and reports: Design custom dashboards to visualize risk scores and provide context for analysts
  • Correlate data: Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior
  • Build custom solutions: Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency
  • Content Development: Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments
  • Data: Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA
  • Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models

Skills

Key technologies and capabilities for this role

SplunkSplunk ESRBARisk-Based AlertingDashboardsAlertsRisk ScoresMachine LearningSecurity Content DevelopmentWorkflow ActionsData Correlation

Questions & Answers

Common questions about this position

What technical skills are required for the Splunk Engineer role?

The role requires deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL), proficiency in scripting languages like Python, PowerShell, or Bash, and strong understanding of security operations, threat detection, incident response, and security frameworks like NIST RMF.

What Splunk certifications are preferred for this position?

Preferred certifications include Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect.

What is the company culture like at True Zero Technologies?

True Zero Technologies has a people-first approach, fostering a community of like-minded, driven, and passionate individuals focused on delivering top-tier services, and has been recognized as one of the Best Places to Work in 2023 and 2025, and on the Inc. 5000 list of fastest-growing companies.

Is this a remote position or does it require office work?

This information is not specified in the job description.

What is the salary or compensation for this Splunk Engineer role?

This information is not specified in the job description.

True Zero Technologies

Cybersecurity services for IT environments

About True Zero Technologies

True Zero Technologies specializes in cybersecurity services and solutions, utilizing technologies such as Splunk, Tanium, and Cribl to provide actionable insights into IT environments for public and private sector organizations. The company's team delivers scalable solutions, shaping large operational and security programs.

11325 Random Hills Rd #360, Fairfax, VA 22030, USAHeadquarters
2016Year Founded
VENTURE_UNKNOWNCompany Stage
ConsultingIndustries
11-50Employees

Land your dream remote job 3x faster with AI