The Role
We’re looking for a Senior Splunk Security Consultant with deep expertise across Splunk Enterprise Security (ES) and Splunk SOAR.
This is a client-facing consulting role covering the full lifecycle from pre-sales and solution design through to hands-on delivery. You’ll work directly with customers to understand their security challenges, shape the right Splunk solution, present recommendations confidently, and then help deliver what has been designed.
You’ll be responsible for:
Supporting pre-sales activity, including discovery calls, technical workshops, solutioning and presentations
Translating customer security requirements into practical Splunk architectures and delivery plans
Designing, configuring and optimising Splunk Enterprise and Splunk ES
Building and tuning correlation searches, detections, notable events and risk-based alerting
Developing Splunk SOAR playbooks and security automation workflows
Onboarding and normalising security data sources, including CIM mapping and data-model design
Writing advanced SPL searches, dashboards, reports and alerts
Integrating Splunk with wider security tooling, APIs and third-party platforms
Leading customer workshops, design reviews and technical demonstrations
Troubleshooting performance, ingestion and platform issues across distributed Splunk environments
Working with SOC and security teams to improve detection coverage and automate response activity
Producing clear technical documentation and handing over solutions effectively to customer teams
What We’re Looking For
Strong hands-on Splunk engineering and consulting experience in enterprise environments
Deep expertise with Splunk Enterprise Security
Hands-on experience with Splunk SOAR, including building and maintaining automated playbooks
Advanced SPL skills and strong knowledge of CIM, data models, field extractions, lookups and knowledge objects
Strong understanding of SIEM, SOC operations, security monitoring, detection engineering and incident response
Experience designing and delivering Splunk security solutions, rather than only administering an existing platform
Comfortable supporting pre-sales, discovery, solution design and scoping
Confident client-facing communicator who can present technical concepts clearly to both technical and non-technical stakeholders
Experience operating Splunk across distributed or high-volume environments
Relevant Splunk certifications are expected, ideally including Enterprise Admin, Architect, Core Consultant and/or security-focused certifications
Additional cyber security certifications are desirable
What’s in It for You?
Long term engagements (12 months+) at market leading rates
Remote first
Work across a variety of complex Splunk security engagements
Combine pre-sales, solution design and hands-on technical delivery
Take ownership of customer outcomes rather than working solely on platform administration
Work closely with experienced cyber security, SOC and engineering teams
Broad exposure across SIEM, detection engineering, security automation and enterprise security architecture
Visa Sponsorship is not possible, all applicants should be Citizens or Green Card holders.
This is a strong fit for an experienced Splunk professional who is technically hands-on, comfortable in front of customers, and able to move confidently between solutioning, consulting and delivery.