Sr Splunk UBA Engineer - ONSITE Job at Simple Solutions, Miami, FL

TnpWUWUvbnhpM1pVNUF1Z0pmTVZHU0svb1E9PQ==
  • Simple Solutions
  • Miami, FL

Job Description

Job Title: Splunk UBA Engineer

3-6 months

onsite - St, Doral, FL 33172, USA

***  MUST HAVE SECRET CLEARANCE***

We are seeking an experienced and analytical Splunk UBA Engineer to implement, optimize, and maintain our User Behavior Analytics (UBA) platform. In this role, you will use behavioral modeling and machine learning capabilities in Splunk UBA to identify insider threats, compromised accounts, data exfiltration, and other advanced attack techniques. You will work closely with SOC analysts, engineers, and data owners to turn user activity data into actionable intelligence and risk-based threat detections.

Key Responsibilities • Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning.

• Deploy UBA cluster designing the build

• Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA.

• Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity.

• Tune and customize threat models to align with organizational risks and reduce false positives.

• Collaborate with the SOC and threat detection teams to operationalize UBA detectionsthrough risk scoring, notable events, and incident response workflows.

• Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations.

• Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage.

• Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities.

• Document procedures, configurations, and threat model customizations.

Qualifications

Required: • 2–4 years of experience in security engineering, threat detection, or security analytics.

• Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection.

• Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.).

• Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts.

• Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats.

• Ability to write clear documentation and communicate findings effectively. Preferred:

• Experience with Splunk Enterprise Security (ES) and/or SOAR integrations.

• Familiarity with MITRE ATT&CK and threat detection frameworks.

• Background in scripting (Python, PowerShell) and API-based data integrations.

• Splunk certifications such as Splunk Core Certified Power User or Splunk UBA Certified Admin.

arning-based anomaly detection and predictive analytics.

Job Tags

Contract work,

Similar Jobs

Alexandria School District 206

Special Education Secretary Job at Alexandria School District 206

Special Education Secretary Location Alexandria, MN : Position: Special Education Secretary/Secretary II Location: Early Education Center...  ...Unit: Minnesota School Employees Association Secretarial/Administrative Assistants FLSA Status: Non-Exempt Position Overview... 

ISSYZONE

PR-Japan Job at ISSYZONE

Position OverviewWe are looking for a proactive and talented Public Relations (PR) Specialist to join our team. The PR Specialist will support the development and execution of effective communication strategies that promote and enhance the brands' image and reputation....

Morris Cancer Center

Support Aide Part Time Days Job at Morris Cancer Center

 ...Job Title: Support Aide Location: RWJ New Brunswick Department: Environmental Services Req#: 0000200723 Status: Part-Time Shift: Day Salary Range: $16.00 - $16.00 Hourly Pay Transparency: The above reflects the anticipated hourly range for this position... 

Monadnock Regional School District

Special Education Administrative Assistant - MRMHS Job at Monadnock Regional School District

 ...Start date 08/20/2025 School year schedule Full benefited position Purpose: Under the direction of the Special Education Administrator, the Administrative Assistant to the Monadnock Regional Middle High School Special Education Administrator is responsible for... 

Corning Incorporated

HR Consultant, Solar Job at Corning Incorporated

 ...Come break through with us. The global Human Resource (HR) Function provides an integrated talent management system that delivers...  ..., and provide guidance on organizational development. The HR Consultant ensures the plant maintains a positive work environment by...