L3 SOC / Splunk

VaporVM · SA

Posted Aug 11, 2026Source: indeed
View & apply on the employer's site ↗

Original posting on indeed. You apply directly with the employer — we never auto-apply.

Job description

**Date Posted:** 11 August, 2026 **Industry:** IT Services and IT Consulting **Location:** VAPORVM IT SERVICES DMCC **Job Description:** -------------------- **L3 SOC / Splunk Engineer — 1 Position** ========================================= **Nationality:** Saudi National **Location:** Saudi Arabia **Department:** Security Operations Center (SOC) **Level:** L3 **Positions:** 1 ### **Job Summary** The L3 SOC / Splunk Engineer will serve as a senior technical resource responsible for advanced threat hunting, complex incident investigation, Splunk architecture and optimization, detection engineering, and technical leadership within the SOC. The engineer will handle the most complex security incidents escalated from L1/L2 and will contribute to improving the overall SOC detection and response capabilities. ### **Key Responsibilities** * Lead investigation of complex and high\-severity security incidents. * Perform advanced threat hunting using Splunk and other security platforms. * Conduct advanced correlation and analysis of security events. * Perform root\-cause analysis for sophisticated security incidents. * Develop advanced Splunk detection and correlation use cases. * Design and optimize Splunk Enterprise Security implementations. * Develop advanced SPL queries and complex correlation searches. * Design and maintain: + Dashboards + Reports + Alerts + Correlation searches + Risk\-based detections + Security monitoring use cases * Perform advanced threat hunting based on: + MITRE ATT\&CK + Threat intelligence + IOCs + TTPs + Emerging threats * Identify gaps in current security monitoring and develop new detection capabilities. * Lead detection engineering and use\-case development. * Perform Splunk performance and search optimization. * Support Splunk data onboarding and normalization. * Work with **CIM (Common Information Model)** and data models. * Support SOAR integration and security automation where applicable. * Provide technical leadership to L1 and L2 SOC engineers. * Review and validate incident investigations. * Lead major incident response activities. * Coordinate with infrastructure, network, cloud, endpoint, and application security teams. * Develop technical incident reports and recommendations. * Participate in SOC architecture and continuous improvement initiatives. * Define and improve SOC processes, playbooks, and operational procedures. * Support compliance and audit requirements. * Provide technical input for new security use cases and security technologies. ### **Required Technical Skills** * Expert\-level knowledge of **Splunk Enterprise Security**. * Advanced **SPL** development skills. * Strong experience with Splunk: + Enterprise Security + CIM + Data Models + Correlation Searches + Risk\-Based Alerting + Dashboards + Reports * Strong experience in SIEM architecture and engineering. * Advanced threat hunting experience. * Strong knowledge of: + Network security + Endpoint security + Cloud security + Identity and access management + Malware analysis concepts + Threat intelligence + Incident response * Strong understanding of MITRE ATT\&CK. * Experience with SOC automation and SOAR is preferred. * Experience integrating multiple security technologies with Splunk. * Strong troubleshooting and analytical skills. * Ability to lead complex security investigations. ### **Experience \& Qualifications** * **7\+ years** of cybersecurity/SOC experience. * **4\+ years of strong hands\-on Splunk experience** preferred. * Significant experience with Splunk Enterprise Security. * Bachelor’s degree in Cybersecurity, Computer Science, Information Security, IT, or related field. * Splunk Enterprise Security certification is highly preferred. * Splunk Core Certified Advanced Power User / Architect certifications are advantageous. * GIAC, CISSP, GCIH, GCIA, GCFA, or equivalent certifications are a strong advantage.

Is this role a fit for you?

Upload any CV — a short AI chat builds your profile, scores how well you fit roles like this across the Gulf, and tailors an ATS-ready CV to each. Free to start. No job promises — you always apply yourself.

Start free — get matched

Similar roles

Listing aggregated from indeed. Built for the Gulf. No job or interview promises — we make your search faster and your CV stronger.