Senior Splunk Engineer
š London, four days a week onsite with the customer
Ā
Company & role
This opportunity sits within a fast growing, people first technology organisation that forms part of a global IT and cyber services provider. They deliver end to end outsourcing and cyber defence solutions across enterprise and regulated clients, with a strong reputation for high quality security delivery.
Ā
You will be embedded with a major financial services customer, acting as the senior Splunk voice across their banking and securities businesses. The focus is on leading enterprise scale log onboarding, detection engineering and monitoring strategy in a highly regulated environment where the quality of security visibility genuinely matters.
This is a hands on, client facing role where you will own delivery from log source assessment through to onboarding, detection design, tuning and continuous improvement.
Ā
Why This Role Stands Out
- Long term embedded engagement with a major financial services client, giving you real depth rather than surface level project work
- You will set the standard for how log onboarding and detection engineering are done across two regulated entities, not just plug into someone else's framework
- Genuine senior authority. You will be the go to voice on onboarding standards, detection coverage and monitoring strategy
- Strong cost versus coverage focus, so the work is commercially sharp as well as technically interesting
- Close collaboration with SOC, detection engineering, incident response, infrastructure, application and database teams across a complex enterprise estate
- Exposure to the full Splunk lifecycle, from ingestion pipelines and data models through to correlation searches, MITRE aligned use cases and platform optimisation
Ā
Key Responsibilities
- Lead end to end log onboarding projects across Linux servers, perimeter applications (web, proxy, firewall, API gateways) and database platforms such as Oracle, SQL Server and Sybase
- Own log source assessment, parsing, normalisation, CIM alignment, data quality validation and onboarding acceptance criteria
- Apply a cost benefit lens to onboarding, prioritising high risk, high value sources over low value, high volume noise
- Design and develop correlation searches, use cases and alerts aligned to MITRE ATT&CK, insider and external threat models, and regulatory requirements
- Tune detection logic continuously to reduce false positives, close coverage gaps and minimise unnecessary platform load
- Partner with the wider Splunk team on ingestion pipelines, parsing accuracy, index design, data models and search performance
- Drive naming conventions, metadata standards, tagging, retention and tiering strategies that balance visibility, performance and cost
- Ensure onboarded data complies with access control, RBAC and regulatory requirements, and support audit and compliance through clear documentation and traceability
- Collaborate with SOC, detection engineering and incident response teams to make sure onboarded logs are actionable and use cases are operationalised properly
- Act as the senior voice and governance lead on onboarding standards, detection coverage and monitoring strategy
Ideal Experience
- Minimum three years hands on experience in security monitoring, log onboarding and detection engineering within a SOC or security operations environment
- Proven delivery of end to end log onboarding projects across Linux, applications and database platforms
- Strong experience designing and implementing correlation rules and monitoring use cases based on real threat scenarios
- Comfortable working across infrastructure, application and database teams to assess sources and shape monitoring requirements
- Deep understanding of attacker tactics, techniques and procedures and the ability to translate them into practical detection content using frameworks such as MITRE ATT&CK
- Hands on Splunk experience, including detection rules, dashboards, data models and writing complex SPL for detection and investigation
- Strong grasp of data prioritisation, filtering, aggregation and summarisation to balance security coverage with platform cost
- Scripting experience with Python or PowerShell to support detection engineering and onboarding automation
Desirable
- Five or more years in security content development, detection engineering and log management within a large scale SOC
- Experience leading enterprise wide onboarding initiatives focused on standardisation and scalability
- Financial services or other regulated sector experience
- Advanced or consultant level Splunk certifications, or recognised cyber security certifications
If you have built your career around making SIEM platforms actually work at enterprise scale, and you want a long term seat at the table with a major regulated client, this one is worth a look.