Senior Splunk Security Engineer – Enterprise Cybersecurity Projects
JCA Associates · Mascate
Job description
About the role
We are seeking an experienced Senior Splunk Security Engineer to lead large‑scale enterprise and government cybersecurity transformation projects across the GCC. You will own end‑to‑end Splunk architecture, implementation and optimisation while working closely with security teams, architects and executive stakeholders.
Key responsibilities
- Design and deliver enterprise Splunk deployments, including Indexer Clusters, Search Head Clusters, Heavy Forwarders, Deployment Servers and multi‑site environments.
- Build and optimise data onboarding pipelines using inputs.conf, props.conf and transforms.conf.
- Develop advanced SPL queries, correlation searches, macros and detection use cases.
- Implement federated search and hybrid SIEM/data‑fabric architectures.
- Integrate Splunk with Cisco security technologies such as Secure Firewall (ASA/FTD), ISE, Umbrella, ThousandEyes, Secure Endpoint, XDR and Meraki.
- Support integration with broader security solutions including Palo Alto Networks, Fortinet, EDR/XDR platforms and PAM/DAM solutions.
- Perform platform health checks, lifecycle management, upgrades, patching and capacity planning.
- Lead technical workshops, architecture discussions and knowledge‑transfer sessions with enterprise customers.
- Produce technical documentation including high‑level and low‑level designs, runbooks and architecture diagrams.
Required profile
- 5+ years of hands‑on Splunk implementation and engineering experience at enterprise scale.
- Deep expertise in Splunk Enterprise Security and a strong understanding of SIEM, SOC and security operations workflows.
- Proven experience integrating Cisco security technologies into Splunk.
- Background in cybersecurity professional services or consulting environments.
- Strong communication and stakeholder‑management skills.
Required skills
- Splunk (Indexer, Search Head, Heavy Forwarder, Deployment Server)
- Splunk Enterprise Security (ES)
- SPL query development
- Cisco Secure Firewall (ASA/FTD), Cisco ISE, Cisco Umbrella, Cisco ThousandEyes, Cisco Secure Endpoint, Cisco XDR, Cisco Meraki
- Palo Alto Networks
- Fortinet
- EDR/XDR platforms
- PAM/DAM solutions
- Network security fundamentals (firewalls, IDS/IPS, VPN)
- SIEM and SOC concepts
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 weeks ago
Expires 1 month from now
20 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
JCA Associates
Mascate