Splunk Dashboard Engineer
Roles and Responsibilities
Design, develop, and maintain Splunk dashboards supporting SOC monitoring, incident detection, investigation, and response.
Create interactive dashboards and visualizations for key security metrics, including:
Incident volume and severity
Mean Time to Detect (MTTD)
Mean Time to Respond/Resolve (MTTR)
Alert fidelity and false positive trends
Develop and optimize Splunk searches, reports, alerts, and dashboard panels to identify suspicious activity and notable security events.
Collaborate with Detection Engineers, Incident Responders, and SOC Analysts to understand operational requirements and threat use cases.
Build dashboards that enable efficient investigation workflows and rapid pivoting from visualization to incident analysis.
Improve dashboard performance by optimizing SPL queries, searches, and data models.
Transform complex and unstructured security data into meaningful visual insights.
Document dashboard logic, search methodologies, metric definitions, and reporting standards.
Ensure dashboards support operational consistency and align with SOC best practices.
Required Qualifications
Hands-on experience developing dashboards, reports, and visualizations in Splunk.
Experience working in a Security Operations Center (SOC) or cybersecurity environment.
Strong experience with Splunk Search Processing Language (SPL).
Experience analyzing security-related data sources, including:
Authentication logs
Endpoint telemetry
Network logs
Application security logs
Ability to convert complex security data into clear, actionable dashboards and reports.
Experience collaborating with SOC Analysts, Incident Responders, and Detection Engineers.
Strong analytical, troubleshooting, and problem-solving skills.
Excellent communication and documentation abilities.