Skip to main content
Posted 18 July, 2026

Splunk ES Engineer

Diverse Lynx
Karnataka Full Time
Reference: 365_569689_26-01722

Splunk Enterprise Security (ES) Engineer (Tier 2 / Tier 3 / PTL)
Key Responsibilities
  • Investigate and resolve complex issues related to Correlation search failures
  • Missing/delayed notable events, Risk-Based Alerting (RBA) anomalies
  • Data model acceleration issues
  • Diagnose performance issues impacting Dashboards, scheduled searches, and notable event generation
  • Conduct in-depth RCA using Splunk ES diagnostic bundles (Search Heads & Indexers)
  • Scheduler metrics and resource utilization data, Identify root causes and implement preventive and corrective actions, Strong analytical and problem-solving skills
  • Expertise in Root Cause Analysis, High attention to detection quality and data accuracy
  • Ability to handle high-severity incidents under pressure
  • Strong communication, leadership, and stakeholder management skills
  • Ownership mindset and continuous improvement focus
  • Utilize advanced SPL to trace the full detection lifecycle:
    Raw logs
    CIM Data Models Correlation Searches Notable Events
  • Optimize detection logic using tstats & accelerated data models
  • Improve detection accuracy, performance, and coverage
  • Common Information Model (CIM) compliance, Data model acceleration and summaries
  • Data mapping. Field extraction, Data normalization
  • Correlation searches, Risk rules and scoring models, Reduce false positives and improve alert fidelity
  • Troubleshoot Search Head Cluster (SHC) issues Captain election, Configuration sync failures
  • Knowledge bundle replication, Ensure system stability and consistency in distributed environments
  • Monitor and tune scheduler performance to Prevent skipped searches, Avoid resource contention
  • Prioritize critical detections
  • Incident triage and investigations, Threat detection workflows, MITRE Telecommunication&CK
  • Threat modeling methodologies
Technical Leadership & Escalation Management (PTL Scope)
  • Lead resolution of critical escalations with end-to-end ownership
  • Provide hands-on support to engineers and technical leads
  • Engage directly with customers to drive resolution and build trust
  • Track escalation progress ensuring accountability and governance
Platform Optimization, Validation & Continuous Improvement
  • Correlation logic and detection use cases, Data models and search performance
  • Validate Splunk ES updates, patches, and enhancements, RCA insights, Product changes
  • Drive continuous improvement initiatives
Mentorship & Customer Advisory
  • Mentor Tier 2 / Tier 3 engineers and technical leads, Conduct knowledge-sharing sessions and training programs,
  • Act as a trusted advisor on Splunk ES optimization, Detection engineering
  • Security monitoring strategies
Technical Expertise and skills
  • Strong experience with Splunk Enterprise & Splunk Enterprise Security (ES)
  • Advanced SPL, Correlation searches & Risk-Based Alerting (RBA), Data Model Acceleration & CIM
  • Expertise in Splunk Search Head Clustering (SHC), Scheduler tuning and performance optimization, Detection engineering and SOC workflows, Splunk Certified Admin (required)
  • Splunk Enterprise Security Certified Admin (preferred)
  • Knowledge of Networking fundamentals (TCP/IP, DNS, HTTP/S)
  • Security frameworks (MITRE Telecommunication&CK)
  • Experience with Cloud platforms (AWS, Azure, GCP), Automation (Python / Shell scripting)
  • Splunk Enterprise & Enterprise Security (ES), JIRA, Git / Version control systems
  • SIEM and security monitoring tools

Sign up for Job Alerts