Salary
💰 $100,000 - $130,000 per year
Tech Stack
FirewallsPythonServiceNowSplunk
About the role
- Lead end-to-end delivery of Splunk SOAR engagements, including requirements gathering, solution design, configuration, and deployment
- Collaborate with client SOC teams to assess automation needs and translate them into playbooks and workflows
- Integrate Splunk SOAR with a wide range of security tools (SIEM, EDR, ticketing, threat intel platforms, firewalls, etc.)
- Provide best-practice guidance on SOAR platform operations, governance, and scalability
- Train and mentor client staff on Splunk SOAR usage, playbook development, and operational workflows
- Conduct performance optimization, troubleshooting, and ongoing support of SOAR solutions
- Collaborate with internal Conducive Consulting teams to contribute to methodology, accelerators, and reusable assets
- Stay current on emerging Splunk features, SOAR capabilities, and security automation trends
Requirements
- Splunk Core Certified Consultant credential (mandatory)
- 3+ years of hands-on Splunk SOAR experience, including playbook creation and integrations
- Strong background in Splunk Enterprise Security (ES) and broader Splunk platform architecture
- Expertise in scripting and automation (Python preferred; familiarity with REST APIs, JSON, YAML)
- Deep understanding of SOC workflows, incident response processes, and threat management
- Experience integrating Splunk SOAR with security solutions such as CrowdStrike, Palo Alto, ServiceNow, MISP, etc.
- Excellent communication, client-facing, and consulting skills
- Ability to work independently and lead client engagements end-to-end
- (Preferred) Experience with multiple SOAR platforms (e.g., Palo Alto Cortex XSOAR, IBM SOAR)
- (Preferred) Splunk Enterprise Security Certified Admin/Implementation certifications
- (Preferred) Previous consulting experience with enterprise clients
- (Preferred) Knowledge of MITRE ATT&CK framework and security operations maturity models