Full-Time

Splunk Engineer

True Zero Technologies

True Zero Technologies

11-50 employees

Splunk-based security and tech-management solutions

No salary listed

Annapolis, MD, USA

In Person

Category
IT & Security (1)
Required Skills
Machine Learning
Computer Networking
Operating Systems
Splunk
Requirements
  • US Background Check Required
  • Splunk Consultant Certification
  • Heavy Splunk ES Experience
  • Experience ingesting logs into Splunk via Cribl is required
  • Experience with Risk-Based Alerting (RBA)
  • Develop and Implement Actionable Alerts and Workflow for Splunk as a SIEM (Security Information and Event Management) tool
  • Develop and Implement Apps & Knowledge Objects (KO) like Dashboard, Reports, Data Models
  • Work with the Splunk Architect/Admin to promote private KO to Global KO
  • Assist, and/or train CISO Splunk Engineering team on Data Lifecycle
  • Support Assist, train, and/or host workshops CISO teams and analysts on Searching and Content Development
  • Develop and implement automation to improve efficiency of CISO workflows using Splunk Assist in development of advanced security use cases in Splunk
  • Develop risk rules and risk incident rules to correlate and alert to significant cyber events
  • Develop custom dashboards specific to RBA (Risk Based Alerting) to highlight risk detail, health analysis and risk suppression
  • Configure incident response and remediation workflows for ES around notable events (RBA or otherwise alerted)
  • Develop custom machine learning (ML) models to support anomaly-detection based augmentation of alerting
  • Work with numerous stakeholders to implement & maintain event logging from various operating systems, applications, identity providers, network infrastructure, and cloud service providers. Understanding of network protocols, operating systems, applications, and device event telemetry
Responsibilities
  • Maintain various clients' Splunk instances with a heavy emphasis on data onboarding, content development, reporting, and visualizations
  • Assist, and/or train CISO Splunk Engineering team on Data Lifecycle
  • Support, train, and/or host workshops with CISO teams and analysts on Searching and Content Development
  • Develop and implement automation to improve efficiency of CISO workflows using Splunk
  • Develop risk rules and risk incident rules to correlate and alert to significant cyber events
  • Develop custom dashboards specific to RBA to highlight risk detail, health analysis and risk suppression
  • Configure incident response and remediation workflows for Enterprise Security around notable events
  • Develop custom machine learning models to support anomaly-detection based augmentation of alerting
  • Work with numerous stakeholders to implement & maintain event logging from various operating systems, applications, identity providers, network infrastructure, and cloud service providers. Understanding of network protocols, operating systems, applications, and device event telemetry
Desired Qualifications
  • Experience supporting federal customers is a plus
True Zero Technologies

True Zero Technologies

View

True Zero Technologies provides security and technology management services by implementing Splunk-based data analytics for organizations in sectors like healthcare, finance, and government. These solutions work by collecting and analyzing large amounts of machine data to help clients monitor their IT systems and detect cybersecurity threats in real-time. As a veteran-owned business, the company differentiates itself by using a team of seasoned industry experts to deliver repeatable, standardized service models rather than one-off custom fixes. Their goal is to ensure long-term customer success through managed services while actively supporting the veteran community through educational scholarships.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Fair Oaks, Virginia

Founded

2016

Simplify Jobs

Simplify's Take

What believers are saying

  • ServiceNow partnership unites AI-driven platforms for enhanced cybersecurity operations.
  • Wiz integration strengthens client cloud security postures via managed services.
  • September 26, 2025 federal award expands government cybersecurity contracts.

What critics are saying

  • Splunk's Q2 2026 agentless pivot obsoletes agent-heavy professional services.
  • Tanium commoditization by Splunk's Terminus acquisition erodes hybrid demand.
  • Booz Allen's January 2026 DoD contract captures public sector Tanium deals.

What makes True Zero Technologies unique

  • True Zero delivers Splunk-based solutions for mission-critical security across sectors.
  • Veteran-owned status secures federal MAS contract worth $571,354 through 2030.
  • Partners with ServiceNow, Wiz, and Tanium for AI-driven cybersecurity services.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

Paid Holidays

401(k) Retirement Plan

401(k) Company Match

Phone/Internet Stipend

Parental Leave