Start Your Search Here

push notification bell

Would you like to receive notifications about Computer and Mathematical Occupations jobs in Charlotte?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

TriOptus LLC

Charlotte / Global

Splunk Security Engineer

Job Description

Senior Privileged Access Monitoring Implementation Specialist

Financial Services Account | Remote - US

Client Location:- Charlotte North Carolina

Duration: 6 months with possible extension

Employment Type: Contract

Work Arrangement: Remote - Onshore/Offshore

About the Role

Our financial services client is seeking a Senior Privileged Access Monitoring Implementation Specialist to design, build, test, and document a production-ready privileged access monitoring solution within the security operations environment.

This role will focus on improving privileged access visibility, security alerting, false-positive reduction, intelligent alert routing, and automation using Splunk SIEM and SOAR technologies .

The ideal candidate will bring strong hands-on Splunk and IAM/PAM experience , along with a background in security monitoring or security operations.

Key Responsibilities

Design and implement monitoring logic for privileged access and identity-related security events.

Develop Splunk correlation searches, custom alert rules, and Risk-Based Alerting (RBA) logic.

Build filtering, suppression, enrichment, and alert-routing rules to improve alert fidelity.

Develop SOAR playbooks and workflows to automate incident handling and alert consolidation.

Integrate SIEM, SOAR, ticketing, and security operations processes.

Develop alert enrichment workflows incorporating user, asset, access, and threat context.

Build Splunk dashboards and reports to monitor alert volume, health, performance, and effectiveness.

Analyze historical data to validate alert accuracy and reduce false positives.

Test monitoring implementations against at least 60 days of historical datasets .

Optimize Splunk searches, data pipelines, field extractions, indexing, and search performance.

Document correlation searches, workflows, playbooks, dashboards, logic, edge cases, and procedures.

Develop operational runbooks and support documentation.

Partner with Security Operations and Security Engineering teams throughout implementation.

Provide knowledge transfer and training to operational teams before engagement completion.

Required Qualifications 4-5+ years of hands-on Splunk experience - must be clearly shown on resume .

4-5+ years of IAM experience - must be clearly shown on resume .

Previous security monitoring / security analyst experience is strongly preferred .

5+ years of experience in security operations, SIEM engineering, security engineering, or related cybersecurity functions.

Advanced experience developing Splunk correlation searches, alerts, dashboards, and reports .

Hands-on experience with Splunk Risk-Based Alerting (RBA) .

Strong knowledge of Splunk data pipelines, field extraction, indexing, search optimization, and alert tuning.

2+ years of hands-on SOAR experience such as Cortex XSOAR, Demisto, or comparable platforms.

Experience developing SOAR playbooks, workflows, automation logic, and incident-response processes.

Experience integrating SOAR with SIEM, ticketing, and security technologies.

2+ years of experience with Privileged Access Monitoring, IAM security, PAM, or related security monitoring use cases .

Understanding of privilege escalation detection, authorization frameworks, access controls, and IAM security.

Proven ability to reduce false positives and improve alert quality in high-volume environments.

Preferred Skills Experience with Cortex XSOAR / Demisto .

PAM solutions and privileged identity monitoring.

Advanced Splunk RBA implementations.

Security automation and alert enrichment.

Experience supporting financial services or other highly regulated environments.

Strong documentation, communication, and stakeholder-management skills.

What We're Looking For

We need a hands-on Splunk + IAM security professional , not simply a general Splunk administrator. The strongest candidates will have demonstrated experience building privileged-access monitoring use cases, tuning security alerts, developing RBA/correlation logic, and automating response through SOAR .

Top 6 Must-Have Skills

Splunk - 4-5+ years

IAM / Privileged Access Monitoring - 4-5+ years

Security Monitoring / SOC Analyst Experience

Splunk Correlation Searches & Risk-Based Alerting

SOAR / Playbook Development

Alert Tuning, Enrichment & False-Positive Reduction

Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location