Posted 18 July, 2026
Splunk ES Engineer
Diverse Lynx
Karnataka
Full Time
Reference: 365_569689_26-01722
Splunk Enterprise Security (ES) Engineer (Tier 2 / Tier 3 / PTL)
Key Responsibilities
Key Responsibilities
- Investigate and resolve complex issues related to Correlation search failures
- Missing/delayed notable events, Risk-Based Alerting (RBA) anomalies
- Data model acceleration issues
- Diagnose performance issues impacting Dashboards, scheduled searches, and notable event generation
- Conduct in-depth RCA using Splunk ES diagnostic bundles (Search Heads & Indexers)
- Scheduler metrics and resource utilization data, Identify root causes and implement preventive and corrective actions, Strong analytical and problem-solving skills
- Expertise in Root Cause Analysis, High attention to detection quality and data accuracy
- Ability to handle high-severity incidents under pressure
- Strong communication, leadership, and stakeholder management skills
- Ownership mindset and continuous improvement focus
- Utilize advanced SPL to trace the full detection lifecycle:
Raw logs CIM Data Models Correlation Searches Notable Events - Optimize detection logic using tstats & accelerated data models
- Improve detection accuracy, performance, and coverage
- Common Information Model (CIM) compliance, Data model acceleration and summaries
- Data mapping. Field extraction, Data normalization
- Correlation searches, Risk rules and scoring models, Reduce false positives and improve alert fidelity
- Troubleshoot Search Head Cluster (SHC) issues Captain election, Configuration sync failures
- Knowledge bundle replication, Ensure system stability and consistency in distributed environments
- Monitor and tune scheduler performance to Prevent skipped searches, Avoid resource contention
- Prioritize critical detections
- Incident triage and investigations, Threat detection workflows, MITRE Telecommunication&CK
- Threat modeling methodologies
- Lead resolution of critical escalations with end-to-end ownership
- Provide hands-on support to engineers and technical leads
- Engage directly with customers to drive resolution and build trust
- Track escalation progress ensuring accountability and governance
- Correlation logic and detection use cases, Data models and search performance
- Validate Splunk ES updates, patches, and enhancements, RCA insights, Product changes
- Drive continuous improvement initiatives
- Mentor Tier 2 / Tier 3 engineers and technical leads, Conduct knowledge-sharing sessions and training programs,
- Act as a trusted advisor on Splunk ES optimization, Detection engineering
- Security monitoring strategies
- Strong experience with Splunk Enterprise & Splunk Enterprise Security (ES)
- Advanced SPL, Correlation searches & Risk-Based Alerting (RBA), Data Model Acceleration & CIM
- Expertise in Splunk Search Head Clustering (SHC), Scheduler tuning and performance optimization, Detection engineering and SOC workflows, Splunk Certified Admin (required)
- Splunk Enterprise Security Certified Admin (preferred)
- Knowledge of Networking fundamentals (TCP/IP, DNS, HTTP/S)
- Security frameworks (MITRE Telecommunication&CK)
- Experience with Cloud platforms (AWS, Azure, GCP), Automation (Python / Shell scripting)
- Splunk Enterprise & Enterprise Security (ES), JIRA, Git / Version control systems
- SIEM and security monitoring tools