Job Title Splunk Engineer Location Remote Contract 12+ Months Description The Principal Splunk Engineer is a part of our Advanced Security Operations Center within Managed Security Services team. This role is designed to provide senior level leadership for the design, engineering, and implementation of security event data collection for our managed security service customers related to incident response, threat monitoring, threat intelligence, and operations. These programs pertain to the data identification, assessment, ingestion, normalization and enrichment activities required for Advanced Security Operations Center to perform proper detection and analytics of cyber threats and response. Lead and perform the content development within Splunk Platform which includes use case creation, dashboard design, tuning of use cases to minimize false positives, development of reporting metrics such as SLA and KPI reports and log source configuration. Threat hunting and independent threat research to augment and feed custom use case creation. Work with the customer to incorporate asset landscape details, severity threats campaigns, and data breaches, as well as perform impact and exposure assessments relative to the customer. Act as an escalation point for the Security Analysts to assist and advise on the most complex security threat investigations. Support and consult vendors and customers to assist in implementing sound and secure logging practices while interfacing with customers in support of their logging requirements. Leverage advanced knowledge of security operations, cyber security tools, intrusion detection, and secured networks to integrate with the SIEM platform. Determine and report the accomplishments of project initiatives across stakeholder groups, providing consulting and guidance on how to drive business results from the data available. Review and enhance logging information flow strategies and technical information flow required for log onboarding create the work plan required for logging onboarding to include determining the technical details. Mentor and support SOC Analysts Tier 1-3. You'll need to have Bachelors degree or four or more years of work experience. Six or more years of relevant work experience. Four or more years of experience as a SIEM Engineer with Splunk, QRadar, RSA Netwitness or other SIEM technology. SIEM administration, configuration, and optimization experience. Threat hunting experience. Experience participating in and acting as an escalation point for complex network threat investigations. Linux command line experience. Knowledge of regular expressions and data normalization. Willingness to travel. Even better if you have Master's degree in information security, cyber security, computer science or a related field. Certifications related to Splunk, QRadar, RSA Netwitness or other SIEM technology. Strong interpersonal skills and collaborative style to enable success across multiple partners. Experience working in a Security Operation Center environment. Cloud experience. Capability to clearly and succinctly explain highly complex issues to senior executives. Strong communication and presentation skills along with the ability to handle multiple priorities in a fast paced dynamic environment. Experience preparing and delivering presentations to peers or senior executives. Ability to negotiate, when warranted, in order to work with other teams. Ability to grasp and assess big picture issues and bring them to light in order to foster positive change for a more robust data ingestion platform and process. EEO Employer Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or .