openleverjobgether
Splunk Enterprise Security Expert
Jobgether
LocationIndia
EmploymentFull-time
Posted2026-08-26T17:27:42.309000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:ce464a5f-b271-4ec9-87b2-632dd0089439
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Splunk Enterprise Security Expert based in India. This role offers the opportunity to shape enterprise-wide Splunk governance and security content architecture at significant scale. You’ll serve as a technical authority across Splunk Enterprise, Enterprise Security, CIM normalization, data models, and knowledge object lifecycle management. Your work will help security teams improve detection quality, search performance, governance, and operational consistency across complex environments. You’ll establish standards, automate processes, and ensure security content moves reliably from development through testing and production. The role combines hands-on engineering with architecture, documentation, cross-functional collaboration, and governance leadership. You’ll work across cloud, infrastructure, security operations, compliance, and detection engineering teams to create scalable and maintainable solutions. This is an ideal opportunity for a seasoned Splunk professional who enjoys solving complex platform challenges and establishing enterprise-level technical standards. Provide centralized governance and lifecycle management for Splunk knowledge objects, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV Store collections. Establish and enforce enterprise-wide naming conventions, taxonomy standards, ownership models, permissions, and lifecycle processes for Splunk content. Audit knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting content and drive consolidation or retirement where appropriate. Develop automation to monitor data ingestion, data flow consistency, normalization drift, and other critical aspects of the Splunk environment. Maintain an enterprise knowledge object registry documenting ownership, scope, purpose, permissions, and lifecycle stage. Collaborate with platform teams to define appropriate permission structures and sharing models across applications, environments, and user groups. Lead the promotion of knowledge objects through development, testing, staging, and production using change control, CI/CD, and GitOps practices. Serve as the enterprise authority for Splunk Common Information Model (CIM) normalization and maintain compliant field mappings across endpoint, network, identity, cloud, and application data sources. Design, build, and maintain Splunk data models supporting Pivot users, Enterprise Security correlation searches, reporting, and risk-based analytics. Manage data model acceleration strategies, including TSIDX, tstats , and summary indexing, while monitoring search load, acceleration performance, and coverage. Define and enforce source-type and index taxonomy standards to improve search performance, configuration consistency, and usability across teams. Ensure asset zones, network zones, identity tiers, and other entity enrichment are incorporated into data models and Enterprise Security frameworks. Maintain CIM coverage matrices connecting data model fields with MITRE ATT&CK techniques, detection use cases, and compliance controls. Own the enterprise Splunk knowledge architecture, including taxonomy hierarchies, content standards, metadata schemas, and classification frameworks. Develop and maintain knowledge management standards covering naming conventions, lifecycle stages, ownership, permissions, CIM mappings, and change control procedures. Lead a cross-functional knowledge governance working group involving detection engineering, SOC operations, platform engineering, compliance, and application teams. Create reusable templates for correlation searches, dashboards, reports, lookups, and macros to accelerate development while maintaining governance standards. Design and implement automation using Python, Bash, GitHub Actions, and rela
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.