Security Analytics Engineer
SIXGENAbout the role
Job Title: Security Analytics Engineer
Position Summary
The Security Analytics Engineer is responsible for engineering, optimizing, and sustaining the enterprise security analytics platform that supports the organization's Security Fusion Center (SFC). This role designs, implements, and maintains security monitoring capabilities by developing advanced detection analytics, optimizing security telemetry, integrating enterprise security tools, and enabling automation across the cybersecurity ecosystem.
The ideal candidate is an expert in Splunk Enterprise Security and the broader Splunk platform, with extensive experience implementing and managing CRIBL data pipelines, security analytics, detection engineering, and enterprise log management. This individual partners with Threat Intelligence, Threat Hunting, Incident Response, and Security Operations teams to ensure security technologies provide timely, high-fidelity detection of evolving adversary tactics, techniques, and procedures (TTPs).
Key Responsibilities
Security Analytics Engineering
- Design, develop, and maintain enterprise security analytics supporting the Security Fusion Center.
- Develop advanced detection logic, correlation searches, dashboards, reports, and alerts to identify emerging cyber threats.
- Continuously improve detection capabilities by developing analytics aligned with current adversary tactics, techniques, and procedures (TTPs).
- Engineer scalable solutions that improve security visibility, operational efficiency, and threat detection effectiveness.
Splunk Platform Engineering
- Administer, configure, and optimize Splunk Enterprise Security (ES), Splunk User and Entity Behavior Analytics (UEBA), and Splunk Security Orchestration, Automation, and Response (SOAR).
- Develop and maintain Splunk searches, correlation rules, risk-based alerting, dashboards, and knowledge objects.
- Optimize data ingestion, indexing, data models, and search performance across large enterprise environments.
- Support lifecycle management, upgrades, performance tuning, and operational maintenance of the Splunk platform.
CRIBL & Security Data Pipeline Engineering
- Design, implement, and maintain CRIBL pipelines to efficiently collect, normalize, enrich, filter, and route enterprise security telemetry.
- Optimize log ingestion and data transformation processes to improve analytics quality while reducing storage and licensing costs.
- Develop parsing, enrichment, and routing logic supporting enterprise detection engineering.
- Integrate data from cloud, endpoint, network, identity, and application security platforms into the Security Fusion Center analytics environment.
Detection Engineering & Security Tool Integration
- Develop and maintain detection analytics supporting proactive identification of advanced cyber threats.
- Evaluate emerging security technologies and recommend enhancements aligned with enterprise cybersecurity strategy.
- Support integration of enterprise security platforms, including SIEM, SOAR, EDR, identity security, vulnerability management, and cloud security tools.
- Collaborate with Threat Hunting and Threat Intelligence teams to operationalize new detections based on emerging threats.
Security Platform Operations
- Operate, maintain, and continuously improve the Security Fusion Center Analytics Platform (SFCAP).
- Support engineering efforts for enterprise security analytics platforms, including custom and commercial solutions.
- Maintain an inventory of enterprise security tools and document system capabilities, integrations, and operational dependencies.
- Support platform reliability, availability, scalability, and security.
Automation & AI
- Implement AI-enabled analytics and automation capabilities to improve ingestion, normalization, enrichment, correlation, and analysis of security telemetry.
- Identify opportunities to automate repetitive engineering and operational tasks.
- Research emerging technologies supporting security analytics, machine learning, and operational efficiency.
- Assist in evaluating AI-enabled security operations capabilities and recommending implementation strategies.
ServiceNow Security Integration
- Develop security use cases supporting enterprise adoption of ServiceNow Security Incident Response (SIR).
- Design and document integrations between ServiceNow and enterprise security platforms.
- Collaborate with operational teams to improve incident workflows through automation and orchestrati
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s