We’ve partnered with a global consultancy and we’re looking for a seasoned Splunk Security Developer / Engineer to join their team. This role is pivotal in maintaining and optimising a large‑scale, hybrid Splunk environment. You’ll work closely with security analysts and infrastructure teams to deliver actionable insights and ensure data integrity across the platform.
What You’ll Be Doing
Design and build advanced Splunk dashboards, visualisations, and custom alerts for operational and security insights.
Develop and manage Splunk Knowledge Objects (KOs) – lookups, field extractions, event types.
Drive data consistency and efficiency through CIM‑compliant Data Models and normalisation.
Collaborate with Cyber Security teams to translate requirements into technical solutions.
Lead end‑to‑end data delivery – from onboarding sources to deployment in Splunk.
What We’re Looking For
5+ years as a Splunk Developer/Engineer in complex enterprise environments.
Strong command of Splunk SPL for advanced queries and optimisation.
Hands‑on experience with data onboarding methods: UF, Syslog, HEC, custom add‑ons.
Knowledge of Data Model acceleration and CIM normalisation.
Experience in hybrid cluster environments and Splunk administration.
Proficiency in Python or Bash for automation tasks.