Sr. Splunk Engineer-KSA

Apply Now β†—
πŸ“ AmmanπŸ“ Amman, , JordanπŸ“ joFull time

About this role

Company Description

IT Security C&T is an innovative, fast-growing security consulting and training company. Our management team combined with our consultants and engineers work together to deliver comprehensive security solutions to our customers around the MENA region.
IT Security C&T is continuously expanding its team of qualified professionals for a wide range of opportunities.Β Interested candidates are required to apply via our Career webpage on our website (www.itsecurityct.com)

Job Description

  • Job Summary:

    The Senior Splunk Engineer will be responsible for the design, implementation, administration, and optimization of Splunk Enterprise or Splunk Cloud within a large-scale enterprise or managed services environment. The engineer will support log onboarding, correlation rule development, dashboard creation, and performance tuning, ensuring the Splunk platform delivers accurate, actionable insights for security operations and compliance monitoring.

    Key Responsibilities:

  • Design and implement end-to-end Splunk solutions including data ingestion, parsing, indexing, and search optimization.
  • Develop and maintain custom correlation rules, alerts, dashboards, and visualizations to support security monitoring and incident response.
  • Onboard new log sources from infrastructure, security, application, and cloud systems using best practices (e.g., via UF, HF, syslog, APIs).
  • Perform regular health checks, indexer and search head performance tuning, license usage monitoring, and configuration backups.
  • Support threat detection initiatives by translating security use cases into actionable Splunk queries and alerts.
  • Assist in troubleshooting ingestion failures, parsing errors, and inefficient searches.
  • Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, completeness, and quality.
  • Maintain Splunk Enterprise Security (ES) configurations, including CIM compliance, notables, and risk-based alerting (RBA).
  • Implement and manage data retention policies and storage utilization in line with compliance requirements.
  • Automate tasks and processes using scripts (Python, Bash, PowerShell) and configuration management tools where needed.
  • Provide technical guidance and mentoring to junior Splunk engineers and analysts.

Qualifications

  • Required Skills & Experience:

  • 5+ years of hands-on experience in SIEM engineering with at least 3 years focused on Splunk Enterprise or Splunk Cloud.
  • Proficient in SPL (Search Processing Language), data onboarding, and CIM normalization.
  • Experience integrating diverse log sources including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intel feeds.
  • Strong understanding of security operations, detection engineering, and incident response workflows.
  • Familiarity with Splunk ES, UBA, ITSI, and SOAR (preferred but not mandatory).
  • Experience with scripting and automation (Python, Bash, PowerShell).
  • Good knowledge of networking, security protocols, and system administration (Windows/Linux).
  • Exposure to regulatory and compliance requirements such as ISO 27001, NCA, SAMA, PCI-DSS, etc.
  • Preferred Certifications:

  • Splunk Core Certified Power User – Required
  • Splunk Enterprise Security Certified Admin – Preferred
  • Splunk Certified Architect or Consultant – Highly Desirable
  • CompTIA Security+, CISSP, or equivalent – Advantageous

Additional Information

Job Location: KSA

Frequently Asked Questions

Is the salary disclosed for the Sr. Splunk Engineer-KSA position at itsecurityct1?
The salary for this Sr. Splunk Engineer-KSA role at itsecurityct1 is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr. Splunk Engineer-KSA position at itsecurityct1 located?
This Sr. Splunk Engineer-KSA role at itsecurityct1 is based in Amman, Amman, , Jordan, jo. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Sr. Splunk Engineer-KSA role at itsecurityct1 full-time or part-time?
This is listed as a Full time position. It is posted as a Sr. Splunk Engineer-KSA role at itsecurityct1.
How do I apply for the Sr. Splunk Engineer-KSA position at itsecurityct1?
Click the "Apply Now" button on this page. You will be redirected to itsecurityct1's official application portal hosted on smartrecruiters where you can submit your application directly.
When was the Sr. Splunk Engineer-KSA job at itsecurityct1 posted?
This Sr. Splunk Engineer-KSA position at itsecurityct1 was posted on Jan 14, 2026. Apply as soon as possible β€” early applications are often reviewed first.
Sr. Splunk Engineer-KSA
itsecurityct1
Apply for this role β†—

You'll be redirected to itsecurityct1's official application page on SmartRecruiters.