Splunk Security Infrastructure Engineer | Splunk Enterprise & Cloud | Qatar

  • Full Time
  • Qatar

Website Workwavez

Location

Qatar – Onsite

Job Category

  • Information Technology (IT) & Software
  • Engineering & Technical
  • Security & Defence
  • Telecommunications
  • Others / Miscellaneous

Job Overview

We are seeking an experienced Splunk Security Infrastructure Engineer to support enterprise security infrastructure and Security Operations Center (SOC) environments in Qatar. The position requires 3–5 years of relevant hands-on experience with Splunk Enterprise and Splunk Cloud, along with strong expertise in Splunk Enterprise Security, Splunk SOAR, security data onboarding, detection engineering, and security infrastructure administration.

The successful candidate will work across Splunk infrastructure, including indexers, search heads, forwarders, and cluster management, while developing advanced SPL searches, correlation searches, detection use cases, and security analytics capabilities. The role also involves integrating security logs from AWS, Azure, and GCP, implementing CIM normalization, and supporting security automation through Splunk SOAR.

This opportunity offers strong career growth and professional development for cybersecurity professionals seeking to deepen their expertise in SIEM, SOC operations, security automation, cloud security, threat detection, and security infrastructure. Candidates must meet the mandatory Splunk experience and certification requirements and should be available to join immediately or within a maximum of 15 days.

Key Responsibilities

  • Administer and maintain Splunk Enterprise and Splunk Cloud environments.
  • Manage Splunk indexers, search heads, forwarders, and clusters.
  • Develop advanced SPL, correlation searches, and security detection use cases.
  • Configure and support Splunk Enterprise Security (ES).
  • Manage Notable Events, Risk-Based Alerting (RBA), threat intelligence, and asset/identity management.
  • Perform security data onboarding and integration.
  • Configure and maintain TAs, props.conf, transforms.conf, and inputs.conf.
  • Implement and maintain CIM normalization.
  • Develop and maintain Splunk SOAR/Phantom playbooks.
  • Create custom functions and API connectors within Splunk SOAR.
  • Develop automation and administrative scripts using Python and Bash.
  • Integrate security logs from AWS, Azure, and GCP environments.
  • Support SOC operations and security infrastructure requirements.
  • Apply security frameworks and methodologies including MITRE ATT&CK, NIST CSF, and CIS Controls.
  • Troubleshoot Splunk infrastructure and security analytics issues.
  • Support continuous improvement of security monitoring, detection, and automation capabilities.

Requirements & Qualifications

Experience

  • 3–5 years of relevant hands-on experience in Splunk security infrastructure and administration.
  • Strong practical experience with Splunk Enterprise and Splunk Cloud.
  • Hands-on experience in SOC and security infrastructure environments.
  • Candidates must be available for immediate joining or within a maximum of 15 days.

Mandatory Technical Skills

  • Splunk Enterprise
  • Splunk Cloud
  • Indexers, Search Heads, Forwarders & Cluster Management
  • Advanced SPL
  • Correlation Searches
  • Detection Use Cases
  • Splunk Enterprise Security (ES)
  • Notable Events
  • Risk-Based Alerting (RBA)
  • Threat Intelligence
  • Asset & Identity Management
  • Data onboarding
  • TAs, props.conf, transforms.conf & inputs.conf
  • CIM normalization
  • Splunk SOAR / Phantom
  • Playbooks
  • Custom Functions & API Connectors
  • Python & Bash scripting
  • AWS / Azure / GCP security log integration
  • SOC & Security Infrastructure

Security Framework Knowledge

  • MITRE ATT&CK
  • NIST Cybersecurity Framework (NIST CSF)
  • CIS Controls

Mandatory Certifications

  • Splunk Core Certified Power User
  • Splunk Enterprise Certified Admin

Preferred Certifications

  • Splunk Enterprise Security Certified Admin
  • Splunk SOAR Certified Automation Developer
  • Security+
  • CySA+
  • CEH
  • CISSP
  • GCIH

Professional Skills

  • Strong analytical and troubleshooting capabilities
  • Security-focused problem-solving skills
  • Ability to work with complex enterprise security infrastructure
  • Strong understanding of SOC operations and security monitoring
  • Ability to collaborate with security and infrastructure teams

Salary, Benefits & Career Growth

Salary

QAR 14,000 per month

Specific additional employee benefits have not been provided in the job description.

This role provides opportunities for career growth and professional development across Splunk administration, SIEM engineering, security analytics, SOC operations, threat detection, cloud security, and security automation.

Professionals can further strengthen their career prospects through advanced Splunk certifications, cybersecurity certifications, technical training, and continuous upskilling in security operations, detection engineering, SOAR, and cloud security.

Application Process

Application Process (Website)

Apply only through the official job link.

Click Apply Now on the website.

Official job link: Not provided in the supplied job description.

HR Email for Application

Send your updated CV directly

Subject Line: Splunk Security Infrastructure Engineer

Important: Please apply only if you meet the mandatory Splunk hands-on experience and certification requirements.

CVs shared through LinkedIn DM or Inbox will not be considered.

To apply for this job email your details to hr@workwavez.com