Demo

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)

ITmPowered
Seattle, WA Full Time
POSTED ON 4/1/2025
AVAILABLE BEFORE 5/1/2025

Splunk Threat Content Developer – Cloud and API Threat Detection – Remote

The experience expected from applicants, as well as additional skills and qualifications needed for this job are listed below.

The Splunk Threat Content Developer will develop, implement, and oversee content development for Threat Detection, Threat Analysis, and Threat Investigations focused on Cloud Security and API Security. Bring your Splunk Content Engineering in Threat Detection, Threat Analysis, Threat Investigation, and Splunk Security Analytics for Cloud (Azure, AWS, SaaS, IaaS, PaaS) as well as API Security / OWASP threats.

Responsibilities :

  • Lead Splunk content development focused on Threat Detection, analytics, investigation, and response for Cloud Security (SaaS / IaaS / PaaS) and API Security (OWASP) threat use cases.
  • Focus on Cloud and API Threat Detection engineering, Content engineering, Splunk Enterprise Security, and Cloud and API Security Threat content.
  • Develop and implement Custom Splunk content and dashboards for analysts on emerging Cloud / API threats.
  • Provide threat visibility and awareness for the Cyber Security organization for new security capabilities.
  • Engineer Splunk content for Cloud / API Security Threat Detection, alerting, dashboards, and IR runbooks.
  • Develop Splunk Content for Cloud / API Security threat use cases including misconfiguration, vulnerabilities, and data exfiltration.
  • Engineer Splunk content to monitor continuously for anomalous API traffic and remediate threats in near real-time.
  • Engineer Splunk content for API Security Threat use cases including authentication issues and security misconfigurations.
  • Engineer cloud threat Splunk correlation searches to provide alerting mechanisms used by the SOC.
  • Review newly ingested data sources for potential security alerts and create dashboards.

Qualifications, Skills, and Experience :

  • Splunk experience and certifications.
  • Strong experience in Splunk content development, building dashboards, reports, and lookup tables.
  • Experience with API Security, Cloud Security, and OWASP.
  • Familiarity with Cloud Security (Azure) and / or Cloud Security Posture Management (CSPM).
  • Programming experience (Splunk SPL, Python, Java, C , Perl, HTML, CSS, Ansible, etc.).
  • Expertise in large scale cyber security data analytics.
  • Implementation, operation, and / or management of SIEM solutions.
  • Experience with common enterprise IT tools and logs (AD / AAD, IAM / MFA, CSPM, etc.).
  • Experience with Windows and Linux tools.
  • Security certifications (GIAC / SANS, ISC (2), EC-Council, etc.).
  • Experience with automating common repeatable tasks using various tools and methods.
  • Information security analysis experience in a Cyber Security Operations Center (CSOC).
  • Soft Skills :

  • Ability to collaborate with others using various project approaches (Agile / Scrum, Waterfall, Gantt Charts).
  • Comfortable working remotely with team members across the country; self-starter with intellectual curiosity.
  • Development of technical documents or presentations – IR / SOC threat runbooks.
  • LOGISTICS :

  • Work remotely anywhere in the Domestic US; preferred locations are Colorado or Georgia.
  • COVID-19 Vaccine and Booster Required – OR must provide valid medical exemption from a doctor in advance.
  • Must be able to successfully pass a 12-panel drug screen, 10-year background check, and employment verification.
  • You must be a current US Citizen or valid Green Card holder; no visa sponsorship available.
  • W2 only – No sub vendors; sponsorship NOT available.
  • Must have direct contact information on your resume (phone / email) to be considered.
  • J-18808-Ljbffr

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)?

    Sign up to receive alerts about other jobs on the Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $117,024 - $149,811
    Income Estimation: 
    $137,568 - $176,908
    Income Estimation: 
    $101,441 - $130,752
    Income Estimation: 
    $111,369 - $141,168
    Income Estimation: 
    $117,871 - $153,580
    Income Estimation: 
    $109,939 - $144,341
    Income Estimation: 
    $114,500 - $144,633
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $120,936 - $155,014
    Income Estimation: 
    $131,745 - $167,716
    Income Estimation: 
    $144,503 - $184,592
    Income Estimation: 
    $102,541 - $137,871
    Income Estimation: 
    $153,752 - $200,235
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at ITmPowered

    ITmPowered
    Hired Organization Address Denver, CO Full Time
    Sr. IT Auditor Consultant, Hospital Medical Device IT Controls Be on the frontlines of Technology Risk in the emerging a...
    ITmPowered
    Hired Organization Address Seattle, WA Full Time
    Sr. Splunk Enterprise Security App Dev / Administrator (Remote) - ITmPowered Sr. Splunk Enterprise Security Developer Ad...
    ITmPowered
    Hired Organization Address Denver, CO Full Time
    Network Security Firewall Engineer - IoT - ITmPowered The Network Security Firewall Engineer focuses on firewall solutio...
    ITmPowered
    Hired Organization Address Boston, MA Full Time
    Sr. IT Auditor Consultant, Hospital Medical Device IT Controls Read all the information about this opportunity carefully...

    Not the job you're looking for? Here are some other Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) jobs in the Seattle, WA area that may be a better fit.

    AI Assistant is available now!

    Feel free to start your new journey!