Splunk UBA Engineer #10519 Job at ECCO Select, Doral, FL

SEtkWWRzUk1yZHBGREZ3d0xYY1gxTU85d3c9PQ==
  • ECCO Select
  • Doral, FL

Job Description

ECCO Select is a talent acquisition and consulting company specializing in people, process and technology solutions. We provide the talent behind the technology enabling our clients to achieve their goals. For more information about ECCO Select, visit us at .

Position Title: Splunk UBA Engineer

Location Information: Doral, FL

Position Responsibilities:

• Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning.

• Deploy UBA cluster designing the build.

• Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA.

• Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity.

• Tune and customize threat models to align with organizational risks and reduce false positives.

• Collaborate with the SOC and threat detection teams to operationalize UBA detections through risk scoring, notable events, and incident response workflows.

• Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations.

• Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage.

• Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities.

• Document procedures, configurations, and threat model customizations.

Essential Skills & Expertise:

• 2–4 years of experience in security engineering, threat detection, or security analytics.

• Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection.

• Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.).

• Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts.

• Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats.

• Ability to write clear documentation and communicate findings effectively.

Qualifications:

• Experience with Splunk Enterprise Security (ES) and/or SOAR integrations.

• Familiarity with MITRE ATT&CK and threat detection frameworks.

• Background in scripting (Python, PowerShell) and API-based data integrations.

• Splunk certifications such as Splunk Core Certified Power User or Splunk UBA Certified Admin.

ECCO Select is committed to hiring and retaining a diverse workforce. Our policy is to provide equal opportunity to all people without regard to race, color, religion, national origin, ancestry, marital status, veteran status, age, disability, pregnancy, genetic information, citizenship status, sex, sexual orientation, gender identity or any other legally protected category. Veterans of our United States Uniformed Services are specifically encouraged to apply for ECCO Select opportunities.

Job Tags

Similar Jobs

Workoo Technologies

Remote Data Entry Specialist - Work from home Job at Workoo Technologies

 ...About the job Remote Data Entry Specialist - Work from home Our company are actually trying to find a workers assistant to do a...  ...keeping managed. Advantages. Health plan. Paid for downtime. Mileage repayment. Personal computer. Cell Phone Gratuity.

Talen Energy

Security Officer - Level I Job at Talen Energy

 ...Security Officer Level I Position Talen Energy is soliciting candidates, for the Fall of 2025, interested in applying for a Security Officer...  ...individuals and vehicle for prohibited items as outlined in Nuclear Regulatory Commission (NRC) Reg. 10CFR73.55. # Armed mobile... 

Inside & Out Maintenance LLC (2)

Hotel Maintenance Technician/Técnico en Mantenimiento Job at Inside & Out Maintenance LLC (2)

 ...records of repairs and completed projects Puesto: Tcnico de Mantenimiento de Hotel (Experiencia en Drywall (yeso) y Pintura) Ubicaci...  ...y parches de drywall en toda la propiedad. Realizar trabajos de pintura y retoques para mantener la apariencia del hotel.... 

Copilot Careers

Substitute Teacher Aide - Entry-Level Role, No Degree or Experience Needed! Job at Copilot Careers

Job Description Substitute Paraprofessional\n District: Forney ISD \n Pay Rate: $90 per day \n Job Description: \n Join our team as a Substitute Paraprofessional and play a vital role in supporting our schools educational mission. When regular staff members...

Encore - PSAV Presentation Services

Event Sales Manager, Hotel Services - Hilton National Mall Job at Encore - PSAV Presentation Services

 ...effectively guiding customers through event experiences, identifying solutions that meet their goals and objectives, resulting in a compelling event experience. Utilizes all available tools to ensure maxim Sales Manager, Hotel, Sales, Manager, Customer Experience, Relationship...