Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)
Company: ITmPowered
Location: San Francisco
Posted on: June 1, 2025
Job Description:
Sr. Splunk Enterprise Security App Developer (Remote) -
ITmPoweredSr. Splunk Enterprise Security App Developer will
develop, create, integrate, and support a highly advanced Splunk
Security application (eSAR) developed internally to detect improper
access to protected data by employees and malicious user activity.
Develop Splunk Apps and add-ons in support of Security Access cyber
threat monitoring, threat management and data compliance across
numerous business critical enterprise applications. Develop
advanced Splunk ES Application functionality. Work with Splunk
Developers using Agile development and administration using Agile
project management methodologies. Work with the Splunk Engineering
team, and support Splunk development, data integrations, and
application administration using Agile methodologies. Splunk
Enterprise Certified Architect OR Splunk Certified Developer
required. Splunk Core Certified Consultant
Preferred.RESPONSIBILITIES:
- Advanced Splunk analytics and the development of custom Splunk
applications
- Splunk data integrations with business-critical enterprise
applications and systems.
- Translating feedback from the business to Splunk technical
requirements and solutions.
- Develop specialized Splunk Security and Compliance
applications, add-ons, data models, dashboards, content using
Python, Splunk SPL, Splunk SimpleXML (OR JavaScript, CSS),
Bash.
- Develop custom Splunk applications and Add-Ons for inclusion of
access events per use case criteria.
- Leverage Modular design to onboard access/security logging
applications and include in incident scoring.
- Onboard access logging applications via modular design
- Develop Splunk Risk scoring based on compliance conditions to
determine suspicious access events.
- Develop custom risk scoring to weed out white noise and only
show actionable incidents to SOC Analysts.
- Develop Dashboards for Security Analysts with detailed drill
down capability for incident response.
- Develop triage workflows for analysts to assign and track
ongoing investigations.
- Develop summary indexing enrichment of access events with IAM
data, Application data, Break-the-Glass logs.
- Aggregate access event data for specific criteria.
- Enable fast searching across fully enriched access events over
long periods of time.
- Develop Break-the-Glass correlations in Splunk for contextual
user access / app data mapping & monitoring.Skills and experience:
- Active Splunk Enterprise Certified Architect or Splunk
Certified Developer - Required at a minimum.
- Splunk Core Certified Consultant - strongly preferred.Required
ExperienceIn addition to active Splunk certification(s), must also
have practical experience with the following:
- Python development - Proficiency in Python programming
language
- Splunk SimpleXML or web development (JavaScript, CSS)
- Splunk app & add-on development
- Splunk data modeling
- Strong experience in Splunk development, building dashboards,
reports and lookup tables.
- Programming experience (Python and Splunk SimpleXML OR
JavaScript, CSS)
- Working knowledge of Splunk including SPL, indexers,
forwarders, search heads
- Experience in OOAD, agile processes, design patterns
- Expertise in large scale cyber security data analytics,
identifying data-driven threat collection opportunities.
- Prior Information security analysis experience in a Cyber
Security Operations Center (CSOC)Soft skills
- Ability to collaborate with others, leveraging many project
approaches (Agile/Scrum, Waterfall, Gantt Charts)
- Comfortable working remotely with team members around the
country. Self-starter with intellectual curiosity
- Development of technical documents or presentations - IR/SOC
threat runbooksLOGISTICS:
- Work remotely anywhere in Domestic US. Preferred locations
Colorado or Georgia.
- Contract role through end of the year with potential for
extension and/or conversion to perm.
- COVID-19 Vaccine and Booster Required - OR must provide valid
medical exemption from doctor in advance.
- Must be able to successfully pass a 12-panel drug screen,
10-year background check, employment verification.
- You will need to be a current US Citizen or valid Green Card
holder. No need for visa now or in future. This role is not able to
offer visa transfer or sponsorship now or in the future.
- W2 only - No sub vendors. Sponsorship NOT available.
- Must have direct contact information on resume (phone / email)
to be considered.
#J-18808-Ljbffr
Keywords: ITmPowered, Cupertino , Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761), IT / Software / Systems , San Francisco, California
Didn't find what you're looking for? Search again!
Loading more jobs...