{"schemaVersion":"jobsearcher.job.v1","id":"7cb1dc59d082e8a2c84374d9","url":"https://jobsearcher.com/jobs/7cb1dc59d082e8a2c84374d9","canonicalUrl":"https://jobsearcher.com/jobs/7cb1dc59d082e8a2c84374d9","title":"Splunk Content Developer","description":"Kinzo Staffing is seeking a Splunk Enterprise Security Engineer who can develop custom detection content (correlation rules) identify threat activity. This includes developing notable events, visualizations, forms, reports, alerts, as well as Splunk Apps, Technology Add-ons, and normalize data sources to the Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The Splunk Engineer will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security app, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.\nWhat you will do:\nAlert use case development\nUpgrade Splunk apps required by Splunk ES upgrades.\nSplunk Enterprise Security administration and management.\nConfigure notable event actions, action menus and Adaptive Responses.\nData onboarding and data ingestion normalization recommendations.\nStrong knowledge of security risk procedures, security patterns, authentication technologies and security attack pathologies.\nDevelop, evaluate, and document, specific metrics for management purpose.\nWrite complex code to install and manage the Splunk enterprise development.\nPerforming maintenance and optimization of existing clustered Splunk deployments.\nCreate Dashboards to monitor the traffic volumes, response times, errors, and warnings across various data centers.\nMonitor the web portals, log files and databases.\nProvide debugging and monitoring capabilities.\nDesign and Develop Splunk for routine use.\nSolve complex Integration challenges and debug complex configuration issues.\nConsult with stakeholders to establish, maintain and refresh their strategic direction in cloud adoption.\nBecome knowledgeable on the CDM technical requirements for the federal government’s CDM program. Understand your role in CDM activities.\nInvolved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.\nDesign, manage, and maintain enterprise SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.\nMaintenance, configuration and implementing products, appliances and devices on the enterprise network.\nQualifications:Required Qualifications:\nBachelor’s degree and 8 years of experience, Master's degree and 6 years of experience. Additional years of relevant experience may be accepted in lieu of the degree.\nAt least 4 years’ experience using customer-focused Splunk Enterprise Security SIEM engineering background - SME knowledge of ES v4.7\nAt least 4 years’ experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments\nAt least 4 years of experience with:\nIn-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise\nDirect experience with Splunk Engineering and data integration\nPrior SIEM data modelling experience on similar platform at scale (>50 servers)\nScripting and development skills in Python/Perl with deep comprehension of regular expressions\nCoordination and communication with other remotely deployed team members\nDeveloping documentation with processes and procedures\nProposing, implementing automation features in a large enterprise environment\nAt least 3 years of experience with Linux and SQL/ODBC interfaces\nAt least 2 years of experience in app interface development, using REST API’s\nHold active Splunk Core Certifications of at least Splunk Architect\nMinimum of 3 year of experience in developing and tailoring reporting from network security tools.\nMust be able to obtain and maintain a US Public Trust clearance.\nPreferred Qualifications:\nExperience with Splunk Common Information Model (CIM) and Enterprise Analytic\nStrong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.\nSelf-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision\nKnowledge of Cloud Services such as AWS, Azure, Office365\nAbility to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell\nExperience in automating Splunk Deployments and orchestration with in a Cloud environment","company":"Kinzo Staffing","rawCompany":"kinzo staffing","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-06T11:50:49.917Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Splunk Content Developer","description":"Kinzo Staffing is seeking a Splunk Enterprise Security Engineer who can develop custom detection content (correlation rules) identify threat activity. This includes developing notable events, visualizations, forms, reports, alerts, as well as Splunk Apps, Technology Add-ons, and normalize data sources to the Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The Splunk Engineer will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security app, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.\nWhat you will do:\nAlert use case development\nUpgrade Splunk apps required by Splunk ES upgrades.\nSplunk Enterprise Security administration and management.\nConfigure notable event actions, action menus and Adaptive Responses.\nData onboarding and data ingestion normalization recommendations.\nStrong knowledge of security risk procedures, security patterns, authentication technologies and security attack pathologies.\nDevelop, evaluate, and document, specific metrics for management purpose.\nWrite complex code to install and manage the Splunk enterprise development.\nPerforming maintenance and optimization of existing clustered Splunk deployments.\nCreate Dashboards to monitor the traffic volumes, response times, errors, and warnings across various data centers.\nMonitor the web portals, log files and databases.\nProvide debugging and monitoring capabilities.\nDesign and Develop Splunk for routine use.\nSolve complex Integration challenges and debug complex configuration issues.\nConsult with stakeholders to establish, maintain and refresh their strategic direction in cloud adoption.\nBecome knowledgeable on the CDM technical requirements for the federal government’s CDM program. Understand your role in CDM activities.\nInvolved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.\nDesign, manage, and maintain enterprise SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.\nMaintenance, configuration and implementing products, appliances and devices on the enterprise network.\nQualifications:Required Qualifications:\nBachelor’s degree and 8 years of experience, Master's degree and 6 years of experience. Additional years of relevant experience may be accepted in lieu of the degree.\nAt least 4 years’ experience using customer-focused Splunk Enterprise Security SIEM engineering background - SME knowledge of ES v4.7\nAt least 4 years’ experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments\nAt least 4 years of experience with:\nIn-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise\nDirect experience with Splunk Engineering and data integration\nPrior SIEM data modelling experience on similar platform at scale (>50 servers)\nScripting and development skills in Python/Perl with deep comprehension of regular expressions\nCoordination and communication with other remotely deployed team members\nDeveloping documentation with processes and procedures\nProposing, implementing automation features in a large enterprise environment\nAt least 3 years of experience with Linux and SQL/ODBC interfaces\nAt least 2 years of experience in app interface development, using REST API’s\nHold active Splunk Core Certifications of at least Splunk Architect\nMinimum of 3 year of experience in developing and tailoring reporting from network security tools.\nMust be able to obtain and maintain a US Public Trust clearance.\nPreferred Qualifications:\nExperience with Splunk Common Information Model (CIM) and Enterprise Analytic\nStrong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.\nSelf-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision\nKnowledge of Cloud Services such as AWS, Azure, Office365\nAbility to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell\nExperience in automating Splunk Deployments and orchestration with in a Cloud environment","datePosted":"2026-08-06T11:50:49.917Z","dateModified":"2026-08-06T11:50:49.917Z","hiringOrganization":{"@type":"Organization","name":"Kinzo Staffing","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7cb1dc59d082e8a2c84374d9"},"url":"https://jobsearcher.com/jobs/7cb1dc59d082e8a2c84374d9"}}