Splunk UBA Engineer Job at 3B Staffing LLC, Miami, FL

RFVpUUxwTTViNmxDS05hY3hyTTZEeGt1alE9PQ==
  • 3B Staffing LLC
  • Miami, FL

Job Description

MUST HAVE SECRET CLEARANCE


Location - 9301 NW 33rd St, Doral, FL 33172, USA


Job Description


Help Job DescriptionCut and paste the job description here.


6/23 - need candidate with more Architect level exp than Angel Romero.

5/5 - WWT owns this work. Onsite - 5 days/week. Will consider candidates who relo to the area. Checking on what specific program this ties into.

MUST HAVE SECRET CLEARANCE

Job Title: Splunk UBA Engineer

We are seeking an experienced and analytical Splunk UBA Engineer to implement, optimize, and maintain our User Behavior Analytics (UBA) platform. In this role, you will use behavioral modeling and machine learning capabilities in Splunk UBA to identify insider threats, compromised accounts, data exfiltration, and other advanced attack techniques. You will work closely with SOC analysts, engineers, and data owners to turn user activity data into actionable intelligence and risk-based threat detections.

Key Responsibilities • Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning.
• Deploy UBA cluster designing the build
• Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA.
• Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity.
• Tune and customize threat models to align with organizational risks and reduce false positives.
• Collaborate with the SOC and threat detection teams to operationalize UBA detectionsthrough risk scoring, notable events, and incident response workflows.
• Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations.
• Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage.
• Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities.
• Document procedures, configurations, and threat model customizations.

Qualifications Required: • 2-4 years of experience in security engineering, threat detection, or security analytics.
• Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection.
• Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.).
• Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts.
• Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats.
• Ability to write clear documentation and communicate findings effectively. Preferred:
• Experience with Splunk Enterprise Security (ES) and/or SOAR integrations.
• Familiarity with MITRE ATT&CK and threat detection frameworks.
• Background in scripting (Python, PowerShell) and API-based data integrations.

Job Tags

Similar Jobs

InSync Healthcare Recruiters

Physician Internal Medicine - Competitive Salary Job at InSync Healthcare Recruiters

 ...a wide range of common chronic and acute medical conditions for patients aged 18 and older...  ...are suggested). Familiarity with E/M coding guidelines and taking charge of medical coding...  ..., medical assistants, nurses, medical billing service, in-house billers, administrative... 

Hartford Healthcare

Patient Care Technician 1 Job at Hartford Healthcare

 ...cutting edge treatment to its patients. This is made possible by...  ...cannot provide the advanced care, expertise and new treatment...  ...ensuring a positive patient experience. This role performs in a high...  ...Hospital Title: Patient Care Technician 1 Location: Connecticut-... 

Headworks, Inc.

Project Manager - Entry Level Job at Headworks, Inc.

 ...striving to make innovative changes within our company and around the globe! POSITION SUMMARY Headworks is seeking an Entry level Project Manager who will work under the supervision of a Senior Manager, assists in the planning, organization, control, integration and... 

VBeyond

Senior Virtual Desktop Engineer Job at VBeyond

 ...applicable) Experience: 5+ years Job Overview: We are seeking a Senior Virtual Desktop Engineer with expertise in Citrix Cloud, VDI, and Azure services to provide third-level support for end-user virtual desktops. The ideal candidate will have deep... 

Deaconess

Patient Care Technician - Cardiac Observation Unit (PCT) - Gateway Job at Deaconess

 ...Patient Care Technician - Cardiac Observation Unit (PCT) - Gateway Job Category: Nursing Support Requisition Number: PATIE015604 Campus...  ...Other Key Words: Entry-Level Patient Care Technician, No Experience Required, Paid Training Provided, On-the-Job Training, Career...