SIEM Engineer – Splunk & Splunk Cloud
Macquarie Park, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are seeking a skilled SIEM Engineer with solid experience in Splunk Enterprise and/or Splunk Cloud to join our security technology team. This position involves managing and supporting enterprise SIEM platforms, integrating new data sources, enhancing threat detection capabilities, and ensuring the reliability of the platform.
Key Responsibilities
- Maintain and engineer Splunk Enterprise and Splunk Cloud environments.
- Oversee components such as indexers, search heads, forwarders, applications, and add-ons.
- Onboard and resolve issues with security logging sources.
- Create, refine and tune SPL queries, alerts, and dashboards.
- Collaborate with SOC teams to meet detection and investigation needs.
- Identify and fix ingestion, search, and system performance problems.
- Integrate data from Microsoft 365, Azure, AWS, Endpoint Detection and Response (EDR), and identity services.
- Work closely with customers, vendors, and internal stakeholders.
- Maintain comprehensive technical documentation and procedures.
- Participate in an on-call rotation, generally 1-2 weeks monthly.
Qualifications and Skills
- Proven expertise with Splunk Enterprise and/or Splunk Cloud.
- Strong command of SPL and general SIEM concepts.
- Experience with Splunk CIM, applications/add-ons, and forwarders.
- Familiarity onboarding security logs from diverse platforms.
- Sound understanding of SIEM operations, SOC functions, and threat detection techniques.
- Knowledge of syslog, APIs, JSON, XML, and regular expressions.
- Advanced troubleshooting capabilities across Linux, Windows, and cloud infrastructures.
- Excellent communication and stakeholder management skills.
- Eligibility to obtain Australian Government Security Clearance.
Preferred Experience
- Background in Google SecOps and YARA-L.
- Knowledge of Microsoft Sentinel and Kusto Query Language (KQL).
- Experience with Sumo Logic or cloud-based SIEM tools.
- Familiarity with Microsoft Defender, Azure Security, or AWS Security platforms.
- Experience working with Palo Alto, CrowdStrike or Security Orchestration Automation and Response (SOAR) platforms.
- Skills in automation, scripting, Git, or Infrastructure as Code.
- Relevant certifications in Splunk, Microsoft, or cybersecurity fields.
About DXC Technology
DXC Technology is a global enterprise technology and innovation company dedicated to providing software, services, and solutions that help businesses harness AI and navigate rapid change. We specialize in Managed Infrastructure Services, Application Modernization, and Industry-Specific Software Solutions, supporting some of the world's most complex technology environments.
Our Culture and Benefits
We foster a supportive environment that prioritizes inclusion, belonging, and corporate social responsibility. Our “people first” approach translates into competitive pay, benefits, ongoing training, and career growth opportunities to positively impact our workforce and communities.
Equal Opportunity Employer
We welcome applicants from diverse backgrounds and embrace a culture where everyone can bring their authentic selves to work. Reasonable accommodations are provided for qualified candidates with disabilities, following our Accommodation Policy.
Work Model and Commitment
We emphasize in-person teamwork while offering flexibility to support personal well-being, productivity, and life balance. Our hiring process is designed to be fair, thorough, and pleasant, allowing candidates to present their best selves and learn about our company.
Recruitment Notice
Please be aware that DXC does not request money at any stage of the hiring process and cautions against fraudulent job offers or communications. We never solicit payment or equipment purchases and do not extend offers via social media.