Security Engineer - SIEM (Splunk) Platform & Operations
Samsung SDS America
| Company | Samsung SDS America |
| Category | Engineering |
| Location | San Jose |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 14 May 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (workable) |
Description
Samsung SDS America (SDSA) serves as the U.S. technology and innovation hub for Samsung’s global enterprise solutions, delivering secure, scalable, and high‑performance IT services that support some of the world’s most complex business environments. As SDSA continues to expand its cloud, mobility, analytics, and cybersecurity capabilities, maintaining a resilient security operations foundation is essential to protecting the company’s digital assets and ensuring uninterrupted service delivery. Position Summary: As Security Engineer, you’ll join the Cybersecurity Operations team, where you’ll serve as the frontline detective monitoring and correlating real‑time threat data from firewalls, cloud assets, EDR, and AI‑driven platforms like Darktrace. You’ll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high‑fidelity alerts. Leveraging your experience SOC environments, you’ll lead deep incident investigations, spearhead proactive threat‑hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: you’ll partner with global engineers, cloud specialists, and incident‑response teams to continuously improve our security posture and document best‑practice playbooks. This is a Full Time Onsite position located in San Jose, CA. Responsibilities: Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats. Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform. Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards Support the onboarding and integration of logs from enterprise systems into the Splunk environment. Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification. Conduct in-depth investigations of security incidents and recommend remediation and containment actions. Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls. Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives. Prioritize remediation efforts based on risk, severity, and business impact. Participate in incident response activities and support threat hunting initiatives as needed. Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture. Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards. Requirements Bachelor’s degree in Computer Science, Information Security, Information Assurance, or a related field; Master’s degree preferred. 3+ years of experience in a cybersecurity operations or related security role. 2+ years of hands-on experience administering Splunk Enterprise Security (ES). Strong hands-on experience with Splunk log ingestion, data normalization, search heads, indexers, SPL query development, and dashboard optimization. Knowledge of detection engineering, correlation rule development, and incident response workflows. Proven experience in threat analysis & incident response. Strong understanding of security log sources, including Windows and Linux servers, firewalls, endpoint tools, cloud infrastructure, and network detecti
986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →