Jobs via Dice
1 week ago Be among the first 25 applicants
Dice is the leading career destination for tech experts at every stage of their careers. Our client, Catapult Solutions Group, is seeking the following. Apply via Dice today!
Splunk UBA Engineer
Onsite | Doral, FL
8 Week Contract
MUST HAVE SECRET CLEARANCE
FOR IMMEDIATE CONSIDERATION, please complete the virtual interview: https://dashboard.catapultsg.com/job/splunk-uba-engineer
We are seeking an experienced and analytical
Splunk UBA Engineer
to implement, optimize, and maintain our User Behavior Analytics (UBA) platform. In this role, you will use behavioral modeling and machine learning capabilities in Splunk UBA to identify insider threats, compromised accounts, data exfiltration, and other advanced attack techniques. You will work closely with SOC analysts, engineers, and data owners to turn user activity data into actionable intelligence and risk-based threat detections.
Key Responsibilities:
Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning. Deploy UBA cluster designing the build Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA. Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity. Tune and customize threat models to align with organizational risks and reduce false positives. Collaborate with the SOC and threat detection teams to operationalize UBA detections through risk scoring, notable events, and incident response workflows. Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations. Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage. Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities. Document procedures, configurations, and threat model customizations.
Qualifications
2–4 years of experience in security engineering, threat detection, or security analytics. Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection. Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.). Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts. Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats. Ability to write clear documentation and communicate findings effectively. Preferred: Experience with Splunk Enterprise Security (ES) and/or SOAR integrations. Familiarity with MITRE ATT&CK and threat detection frameworks. Background in scripting (Python, PowerShell) and API-based data integrations. Splunk certifications such as Splunk Core Certified Power User or Splunk UBA Certified Admin.
Seniority level
Seniority level Mid-Senior level Employment type
Employment type Full-time Job function
Job function Engineering and Information Technology Industries Software Development Referrals increase your chances of interviewing at Jobs via Dice by 2x Sign in to set job alerts for “Engineer” roles.
Engineer-General Maintenance-Full Time *$500 Sign-on Bonus
Engineer - Railway Operations & Maintenance (Relocation Offered)
Quality Engineer: Continuous Improvement
Hialeah, FL $80,000.00-$110,000.00 5 days ago Hialeah, FL $105,000.00-$115,000.00 4 weeks ago Miami, FL $105,000.00-$115,000.00 4 weeks ago Hialeah, FL $90,000.00-$110,000.00 1 week ago Miami, FL $85,196.00-$106,495.00 1 day ago Development Review Services Engineering Manager - PE
Hialeah, FL $95,000.00-$110,000.00 5 days ago 1st Shift - Part Time - As Needed - Building Engineer
Hollywood, FL $90,000.00-$110,000.00 1 month ago We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr
Splunk UBA Engineer
Onsite | Doral, FL
8 Week Contract
MUST HAVE SECRET CLEARANCE
FOR IMMEDIATE CONSIDERATION, please complete the virtual interview: https://dashboard.catapultsg.com/job/splunk-uba-engineer
We are seeking an experienced and analytical
Splunk UBA Engineer
to implement, optimize, and maintain our User Behavior Analytics (UBA) platform. In this role, you will use behavioral modeling and machine learning capabilities in Splunk UBA to identify insider threats, compromised accounts, data exfiltration, and other advanced attack techniques. You will work closely with SOC analysts, engineers, and data owners to turn user activity data into actionable intelligence and risk-based threat detections.
Key Responsibilities:
Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning. Deploy UBA cluster designing the build Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA. Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity. Tune and customize threat models to align with organizational risks and reduce false positives. Collaborate with the SOC and threat detection teams to operationalize UBA detections through risk scoring, notable events, and incident response workflows. Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations. Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage. Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities. Document procedures, configurations, and threat model customizations.
Qualifications
2–4 years of experience in security engineering, threat detection, or security analytics. Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection. Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.). Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts. Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats. Ability to write clear documentation and communicate findings effectively. Preferred: Experience with Splunk Enterprise Security (ES) and/or SOAR integrations. Familiarity with MITRE ATT&CK and threat detection frameworks. Background in scripting (Python, PowerShell) and API-based data integrations. Splunk certifications such as Splunk Core Certified Power User or Splunk UBA Certified Admin.
Seniority level
Seniority level Mid-Senior level Employment type
Employment type Full-time Job function
Job function Engineering and Information Technology Industries Software Development Referrals increase your chances of interviewing at Jobs via Dice by 2x Sign in to set job alerts for “Engineer” roles.
Engineer-General Maintenance-Full Time *$500 Sign-on Bonus
Engineer - Railway Operations & Maintenance (Relocation Offered)
Quality Engineer: Continuous Improvement
Hialeah, FL $80,000.00-$110,000.00 5 days ago Hialeah, FL $105,000.00-$115,000.00 4 weeks ago Miami, FL $105,000.00-$115,000.00 4 weeks ago Hialeah, FL $90,000.00-$110,000.00 1 week ago Miami, FL $85,196.00-$106,495.00 1 day ago Development Review Services Engineering Manager - PE
Hialeah, FL $95,000.00-$110,000.00 5 days ago 1st Shift - Part Time - As Needed - Building Engineer
Hollywood, FL $90,000.00-$110,000.00 1 month ago We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr