Summer 2025

IoT Software Engineer Intern

Posted on 4/23/2025

Splunk

Splunk

5,001-10,000 employees

Real-time machine data analytics for IT

Compensation Overview

$42 - $50/hr

Company Historically Provides H1B Sponsorship

Boulder, CO, USA

Hybrid

Hybrid role; specific in-office days not mentioned.

Category
Software Engineering (2)
,
Required Skills
Software Testing

Get referred to Splunk

Find people who can refer or advise you

Requirements
  • Actively pursuing a Bachelors or Master's in Computer Science, Software Engineering, Computer Engineering, Electrical Engineering, Mathematics or a related technical field, and a strong record of academic achievement
  • At least one semester/quarter remaining to complete after the internship
  • Available to work 40 hours a week for 12 weeks
Responsibilities
  • You will design, develop, code and test software systems, or applications for software improvements and new products
  • You will actively contribute through participation in agile development of project timelines, implementation design specifications, system flow diagrams, documentation, testing, and ongoing support of systems
  • We will encourage you to live innovation by promoting and soliciting ideas within project teams
Desired Qualifications
  • Knowledge of software engineering processes, agile framework, tools (e.g.: programming proficiency in a language, preferably Python), methods, test development, algorithms and data structures
  • Familiarity with object-oriented programming concepts, large-scale software architecture, networking and distributed systems, and UNIX/Linux environments
  • Experience working in Python
  • Exposure to working with Embedded Systems
  • Exposure to Linux development
  • Exposure to Front-end technologies such as React, and back-end technologies such as Spring Boot and Flask
  • Demonstrate competency and aptitude for Analytics, machine learning, AI, statistics, information retrieval, linguistic analysis

Splunk analyzes large sets of machine data from IT systems, IoT devices, and security tools to provide real-time insights through its Data to Everything platform. It collects, searches, analyzes, and visualizes data so teams can monitor infrastructure, detect issues, and make informed decisions quickly. It differentiates itself by ingesting diverse data sources across IT, security, and business analytics, offering cross-domain visibility and security insights at scale, with integrations to technologies like Palo Alto Networks and Cisco. Its goal is to help organizations improve operational efficiency and security posture by turning data into actionable insights.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

San Francisco, California

Founded

2003

Get referred to Splunk

Find people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • NetApp Splunk SOAR playbook released June 2026 automates ransomware containment at storage layer, reducing mean time to contain.
  • eSentire Atlas integration now lets SOC analysts remotely query Splunk logs via Atlas Actions without local UI access.
  • Cisco XDR integration with Splunk SOAR creates closed-loop agentic SOC model, saving over nine hours of analyst toil at RSAC 2026.

What critics are saying

  • CVE-2026-20253 unauthenticated RCE in Splunk Enterprise below 10.2.4 enables arbitrary code execution and log manipulation; CISA confirms active exploitation.
  • Repeated critical vulnerabilities since 2024 erode enterprise trust, prompting migration to Microsoft Sentinel, Palo Alto, or CrowdStrike.
  • Cisco's integration of Splunk into XDR suites risks deprioritizing Splunk as standalone product, with David Dalling now GVP Splunk Security at Cisco.

What makes Splunk unique

  • Splunk Enterprise Security enables deeper threat hunting and investigation than Cisco XDR, per RSAC 2026 findings.
  • Splunk's Data to Everything platform transforms machine data into real-time actionable insights for large enterprises across IT and security.
  • Splunk SOAR automates incident response workflows, moving context between systems without forcing analysts to manually re-enter evidence.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental and vision insurance plans for regular, full-time U.S. employees — choose the best plans for you and your family. Plus: Health Savings Account (HSA), Life insurance and survivor benefits, Flexible Spending Accounts (FSA), Business travel and accident insurance, Voluntary Critical Illness & Hospital Indemnity

Eligible employees enjoy: 401(k) Plan with a company match, Employee Stock Purchase Plan (ESPP), Equity awards, Bonus or commission program

We support you and your family: Paid parental leave, Mother rooms and wellness rooms, Family Planning

Your work/life balance is important to us, that's why we offer: 16 company holidays, 15 vacation days, 10 sick days, 10 bereavement days, 5 volunteer days

Ensuring our employees' success goes beyond insurance plans: Education reimbursement, Electric car charging stations, Employee Assistance Program (EAP), Stocked kitchens, Gym discounts/onsite fitness centers, Pet insurance discount, Student loan resources, Cool workspace with collaborative environments, 529 College Savings Plan

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

3%

2 year growth

4%
voco Hotels by IHG
Jun 9th, 2026
NetApp (NTAP): storage as strategic AI & security control plane.

NetApp (NTAP): storage as strategic AI & security control plane. 3h ago · 0:00 listen · Source: simplywall.st Summary. NetApp, Cisco, and Splunk have expanded their collaboration, launching new FlexPod AI solutions and a NetApp Splunk SOAR playbook. This initiative automates incident response at the storage layer to boost cyber resilience and AI deployment efficiency. What's interesting is this deep integration ties NetApp's core storage platform directly to customers' AI and ransomware defense workflows. This development highlights how NetApp is working to turn storage into a strategic AI and security control plane. The company reported US$6,925 million in revenue and US$1,276 million in net income for 2026. They are guiding fiscal 2027 revenue to between US$7,325 million and US$7,575 million, with operating margins projected at 22.1% to 23.1%. The bottom line is these new offerings could reshape NetApp's investment narrative by reinforcing demand for AI and cyber-resilient infrastructure. This is an AI-generated audio summary. Always check the original source for complete reporting.

SMEChannels
Jun 3rd, 2026
NetApp and Cisco deepen cyber resilience alliance with automated ransomware response at the data layer.

NetApp and Cisco deepen cyber resilience alliance with automated ransomware response at the data layer. Jun 3, 2026 - 14:56 Expanding their long-standing collaboration, NetApp and Cisco have introduced a new Splunk SOAR playbook that enables enterprises to automate ransomware containment directly at the storage layer, accelerating response times and minimizing data loss. NetApp, a leading Intelligent Data Infrastructure company, and Cisco, today announced an expansion of their collaboration to help customers strengthen defense-in-depth strategies for customers. Combining Intelligent Data Infrastructure with advanced analytics and observability capabilities, NetApp and Splunk have delivered deep, real-time visibility into storage and infrastructure health. Together, they are helping customers turn operational data into actionable insights that improve reliability, security, and business outcomes. By expanding their collaboration with the new NetApp Splunk Security Orchestration, Automation, and Response (SOAR) playbook, NetApp and Splunk are helping joint customers contain ransomware attacks and limit data loss at the storage layer, enhancing the containment of the blast radius of cyberattacks while increasing the speed and reducing the cost of recovery. "With AI accelerating both the speed and sophistication of cyberattacks, the window to respond has never been smaller," said Sandeep Singh, Senior Vice President and General Manager, Platform at NetApp. "To limit the cost and impact of ransomware, organizations must act the moment a threat is detected, which means extending security automation into the storage layer where data lives. As the company delivering the most secure storage on the planet, NetApp is uniquely positioned to make storage an active part of a defense-in-depth strategy. By working with Cisco to enable Splunk SOAR workflows to take direct action on data stored in NetApp ONTAP(R), we're helping make a defense-in-depth security strategy simpler and more effective." "With AI accelerating both the speed and sophistication of cyberattacks, the window to respond has never been smaller. To limit the cost and impact of ransomware, organizations must act the moment a threat is detected, which means extending security automation into the storage layer where data lives. As the company delivering the most secure storage on the planet, NetApp is uniquely positioned to make storage an active part of a defense-in-depth strategy. By working with Cisco to enable Splunk SOAR workflows to take direct action on data stored in NetApp ONTAP, we're helping make a defense-in-depth security strategy simpler and more effective." - Sandeep Singh, Senior Vice President and General Manager, Platform, NetApp To give customers the resiliency and flexibility they need to protect their data, Cisco and NetApp are releasing the NetApp Splunk SOAR playbook. Splunk Enterprise Security is already integrated with NetApp Ransomware Resilience to collect analytics from the data layer, enhancing incident triage and prioritization. With the new playbook, Splunk SOAR users can now use those signals as well as signals from other solutions to automatically take incident response actions directly on NetApp ONTAP storage as an integral part of their incident response. These actions include blocking a suspicious user, taking snapshots of the data and taking data volumes offline to protect against further infection. As a result, customers will be better able to contain ransomware attacks and limit data loss at the storage layer. Utilized as part of the organization's defense in depth security strategy, the NetApp Splunk SOAR playbooks help to strengthen collaboration between security and storage teams. "Effective security strategies require visibility and action across the entire technology stack, including the data layer. With the new NetApp Splunk SOAR playbook, ONTAP storage becomes an active participant in the security ecosystem, enabling organizations to contain threats directly targeting enterprise data. By connecting NetApp storage into Splunk SOAR workflows, we're helping security and storage teams collaborate more seamlessly and respond to incidents with greater speed and confidence." - David Dalling, Group Vice President, Splunk Security, Cisco Automating the response and recovery actions against cyber threats with the NetApp Splunk SOAR playbook improves security team metrics like mean time to contain (MTTC) and reduces the manual effort and skills required to protect data. As a result, NetApp and Cisco are making it faster and more efficient for enterprises to achieve cyber resilience. "Effective security strategies require visibility and action across the entire technology stack, including the data layer," said David Dalling, GVP, Splunk Security at Cisco. "With the new NetApp Splunk SOAR playbook, ONTAP storage becomes an active participant in the security ecosystem, enabling organizations to contain threats directly targeting enterprise data. By connecting NetApp storage into Splunk SOAR workflows, we're helping security and storage teams collaborate more seamlessly and respond to incidents with greater speed and confidence." "The partnership between Splunk and NetApp helps customers run their businesses more securely and effectively, connecting operations across storage and security teams. By giving customers real-time visibility into what's happening across their environments, NetApp and Splunk enable enterprises to reduce disruption and optimize performance so they can use their data to drive measurable business outcomes." - Dallas Olson, Chief Commercial Officer, NetApp "The partnership between Splunk and NetApp helps customers run their businesses more securely and effectively, connecting operations across storage and security teams," said Dallas Olson, Chief Commercial Officer at NetApp. "By giving customers real-time visibility into what's happening across their environments, NetApp and Splunk enable enterprises to reduce disruption and optimize performance so they can use their data to drive measurable business outcomes." The NetApp Splunk SOAR playbook is now available to download from SplunkBase.

Dr. Mercy Nwankwo
Apr 5th, 2026
OCSF explained: the shared data language security teams have been missing.

OCSF explained: the shared data language security teams have been missing. Welcome to the world of Open Cybersecurity Schema Framework (OCSF). Hey there, security enthusiasts! While the industry has been buzzing about models, copilots, and agents, there's a silent revolution happening beneath the surface. Vendors are now rallying around a shared language to describe security data, and leading this charge is the Open Cybersecurity Schema Framework (OCSF). OCSF offers a common ground for vendors, enterprises, and practitioners to represent security events, findings, objects, and context. This means less time spent on translating field names and parsers, and more time on actually analyzing and correlating data. In a world where security teams are juggling multiple sources of telemetry, OCSF is like a dream come true, offering a unified infrastructure that was once just a distant hope. Unlocking OCSF's potential. OCSF is an open-source framework designed for cybersecurity schemas, offering a vendor-neutral and format-agnostic approach. It provides application teams and data engineers with a shared structure for events, enabling analysts to work with a consistent language for threat detection and investigation. Now, let's dive into the real-world impact of OCSF within a security operations center (SOC). Imagine having to normalize data from various tools to correlate events and detect anomalies. OCSF simplifies this process by helping vendors align their schemas into a common model, streamlining data flow across different platforms without the need for extensive translations. The rise of OCSF. In the past two years, OCSF has gained significant momentum. Initially launched in August 2022 by Amazon AWS and Splunk, the project has garnered support from industry giants like Cloudflare, CrowdStrike, IBM, and many others. The community has rapidly expanded, with over 900 contributors now part of the OCSF ecosystem. OCSF: transforming the industry. Across the observability and security landscape, OCSF is making its mark. From AWS Security Lake to Splunk's data processing capabilities, OCSF is seamlessly integrated into various products and services. Palo Alto Networks, CrowdStrike, and other key players are leveraging OCSF to enhance data interoperability and streamline security operations. Embracing AI with OCSF. As AI technologies become more prevalent in cybersecurity, OCSF plays a crucial role in enabling teams to understand and analyze AI-generated telemetry. With OCSF's latest updates, security teams can better track AI-driven actions and identify potential security threats. Looking ahead with OCSF. Imagine a future where OCSF helps unravel complex AI interactions and safeguards sensitive data. With upcoming updates like OCSF 1.8.0, security teams can gain deeper insights into AI behaviors and mitigate risks more effectively. Join the OCSF revolution. As OCSF continues to evolve into a standard practice in the cybersecurity realm, it offers a unified framework that enhances data security and operational efficiency. In a world where data protection is paramount, OCSF serves as a vital tool for safeguarding sensitive information and combating evolving security threats.

Business Wire
Mar 31st, 2026
Resecurity launches native Splunk integration for real-time cyber threat intelligence

Resecurity, a cybersecurity and threat intelligence company, has launched a native integration with Splunk through a dedicated app on Splunkbase. The integration allows organisations to connect Resecurity's cyber threat intelligence with Splunk's ecosystem, enabling the ingestion of indicators of compromise and indicators of attack into Security Information and Event Management and Security Operations Center workflows. The app uses the TAXII protocol to facilitate threat intelligence feeds, allowing cybersecurity teams to correlate actionable intelligence with internal telemetry. Once ingested, the indexed data can enrich logs and accelerate visibility by providing additional context for analysis and investigation. Founded in 2016, Resecurity was recently named one of the top 10 fastest-growing private cybersecurity companies in Los Angeles by Inc. Magazine.

Carroll County News
Mar 31st, 2026
Resecurity introduces native integration with Splunk.

Resecurity introduces native integration with Splunk. * 3 hrs ago Resecurity (USA), a global cybersecurity and threat intelligence company trusted by Fortune 100 enterprises and government agencies, announced the implementation of a native integration with Splunk, delivered through a dedicated app published on Splunkbase. Resecurity introduces native integration with Splunk (SIEM). This seamless integration enables organizations of any size to connect Resecurity's cyber threat intelligence (CTI) with the Splunk global ecosystem, facilitating the timely ingestion of indicators of compromise (IOCs) and indicators of attack (IOA), along with ongoing enrichment of security events and logs within existing monitoring and investigation workflows. Through the Splunk app, cybersecurity teams can ingest threat intelligence feeds from Resecurity into Security Information and Event Management (SIEM) and Security Operations Center (SOC), using industry-standard mechanisms such as the TAXII protocol. This enables organizations to incorporate actionable intelligence from Resecurity and correlate it with internal telemetry. Once ingested, indexed threat intelligence data can be used to enrich logs and accelerate visibility by providing additional context for analysis, alerting, and investigation. The app is available via Splunkbase and can be deployed within Splunk Enterprise environments, allowing organizations to configure unparalleled ingestion and data analysis based on their operational requirements: Resecurity Threat Intelligence Resecurity continues to expand its integration ecosystem by supporting interoperability with widely adopted platforms and applications, enabling organizations to make effective use of threat intelligence in daily operations. About Resecurity Resecurity(R) is a cybersecurity company that delivers a unified endpoint protection, fraud prevention, risk management and cyber-threat intelligence platform. Known for providing best-of-breed, data-driven intelligence solutions, Resecurity's services and platforms focus on early-warning identification of data breaches and comprehensive protection against cybersecurity risks. Founded in 2016, it has been globally recognized as one of the world's most innovative cybersecurity companies with the mission of enabling organizations to combat cyber threats regardless of their sophistication. Most recently, by Inc. Magazine, Resecurity was named one of the Top 10 fastest-growing private cybersecurity companies in Los Angeles, California. Resecurity is a member of InfraGard National Members Alliance (INMA), AFCEA, NDIA, SIA, FS-ISAC and several American Chambers of Commerce worldwide. To learn more, visit https://resecurity.com.

INACTIVE