Splunk Engineer (Sydney)

Splunk Engineer (Sydney)

03 Aug
|
PAAR Systems
|
Sydney

03 Aug

PAAR Systems

Sydney

Splunk Enterprise Security (ES) | Detection Engineering | Incident Support

Location: [On-site / Hybrid / Remote] Type: Full-time Team: Security Operations Centre

Role Overview

Paar Systems is seeking a hands‐on Splunk Engineer to administer, optimise and extend our Splunk Enterprise Security (ES) environment. The role spans platform administration, detection engineering, data onboarding, and advanced support for incident investigations.

You will work closely with SOC analysts to strengthen detection and response workflows, integrate Splunk with the broader security tooling ecosystem, and ensure the platform remains performant, well‐documented and audit‐ready.

Key Responsibilities

Platform Administration

- Administer and maintain the Splunk Enterprise Security (ES) environment.
- Manage index lifecycle, retention policies, and storage optimisation.

Detection Engineering

- Develop, optimise, and maintain correlation searches and use cases.
- Align detections with frameworks like MITRE ATT&CK.;
- Create and enhance Splunk dashboards, reports, and alerts.

Data Onboarding

- Integrate new log sources and data inputs (cloud, network, endpoint, apps).
- Normalise and onboard logs using CIM (Common Information Model).
- Tune data models, tags, and event types.
- Provide advanced support for incident investigations escalated from L1/L2.
- Conduct deep forensic analysis using Splunk data.
- Support incident response activities and root‐cause analysis.
- Work closely with SOC analysts to improve detection and response workflows.

Integrations

- Integrate Splunk with SOAR platforms.




- Support API integrations with external security tools.

Performance & Optimisation

- Investigate issues with data ingestion, latency, and inputs.
- Optimise queries and reduce search execution time.

Documentation & Enablement

- Maintain Splunk architecture documentation and SOPs.
- Support audits and reporting requirements.
- Conduct knowledge sharing and training for L1/L2 analysts.

Technical Skills Required

Splunk Expertise

- Solid hands‐on experience with:
- Splunk Enterprise Security (ES).
- Search Processing Language (SPL) for advanced searches and correlation rules.
- Dashboards, reports, alerts, and data models.
- Common Information Model (CIM) and log normalisation.
- Index management, retention, and storage optimisation.
- Data onboarding from cloud, network, endpoint, and application sources.

Security & SOC

- Solid understanding of SIEM operations, threat detection, and incident response.
- Familiarity with the MITRE ATT&CK; framework and detection‐engineering practices.
- Experience supporting forensic analysis and root‐cause investigations.

Integrations & Automation

- Experience integrating Splunk with SOAR platforms and external security tools via APIs.
- Working knowledge of scripting (e.g., Python) for automation and data handling.
- Splunk certifications (e.g., Splunk Core Certified Power User, Admin, or ES Certified Admin).
- Experience with cloud platforms (AWS, Azure, or GCP) and cloud log ingestion.
- Exposure to other security tooling (EDR, firewalls, IDS/IPS, threat intel feeds).
- Understanding of regulatory and compliance requirements relevant to the client's sector.

#J-18808-Ljbffr

📌 Splunk Engineer (Sydney)
🏢 PAAR Systems
📍 Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (sydney) / sydney

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (sydney) / sydney