Splunk Onboarding Content Engineer

Posted 12 Hours Ago
Be an Early Applicant
Memphis, TN, USA
In-Office
Entry level
Financial Services
The Role
Coordinates application log onboarding into Splunk from discovery through production validation. Partners with technical and business stakeholders to assess telemetry, troubleshoot data pipelines, normalize events, and address sensitive-data requirements. Develops dashboards, alerts, reports, correlation searches, and documentation for security, compliance, fraud, troubleshooting, and operational use cases. Leads workshops, validates content, tunes detections, manages onboarding status, and provides guidance to application teams.
Summary Generated by Built In

Splunk Onboarding and Content Engineer

Business Area: Information Security — Security Operations
Work Arrangement: On-site (Memphis area preferred, other metro areas where First Horizon has office space may be considered)

Summary

We are seeking a Splunk Onboarding and Content Engineer to help application teams turn their security, audit, operational, and business logs into useful, reliable Splunk capabilities. This role will coordinate onboarding from initial discovery through production validation, then partner with application owners to develop dashboards, alerts, reports, and other content that improves visibility, investigation, compliance, and operational decision-making.

The ideal candidate combines strong stakeholder coordination with hands-on Splunk development. You can translate business and technical questions into data requirements, guide teams through onboarding dependencies, validate that logs are usable and appropriately protected, and create practical content that application owners will adopt.

Key Responsibilities

·       Serve as the primary coordinator for application log onboarding into Splunk, managing intake, discovery, requirements, dependencies, testing, production readiness, and handoff.

·       Partner with application owners, developers, infrastructure teams, security teams, risk partners, and vendors to identify available log sources, transport methods, environments, owners, retention needs, and priority use cases.

·       Assess proposed log sources for security, audit, compliance, fraud, troubleshooting, and operational value; help teams distinguish required telemetry from low-value or duplicative data.

·       Gather and document host names, file paths, APIs, database connections, cloud services, event streams, authentication requirements, network dependencies, service accounts, and sample events needed for onboarding.

·       Coordinate onboarding across common collection methods, including universal forwarders, syslog, APIs, database connectors, cloud integrations, event hubs, and supported Splunk add-ons.

·       Validate data flow, timestamp accuracy, source and sourcetype assignment, field extraction, event breaking, permissions, completeness, and search performance.

·       Normalize and enrich data using the Splunk Common Information Model, field aliases, calculated fields, tags, event types, lookups, and supporting reference data.

·       Develop and maintain dashboards, alerts, correlation searches, reports, scheduled searches, drilldowns, and reusable search content aligned with application-owner needs.

·       Facilitate use-case workshops that translate questions such as who accessed an application, what administrative changes occurred, whether privileged access was elevated, and which high-risk events require notification into Splunk content.

·       Test alerts and dashboards with stakeholders, tune thresholds and logic, reduce false positives, and document expected behavior, ownership, response procedures, and escalation paths.

·       Identify sensitive information in logs and coordinate with data owners and security partners to address masking, minimization, access, and retention requirements before production use.

·       Troubleshoot onboarding issues involving connectivity, stale or missing data, log permissions, malformed events, unsupported platforms, add-on compatibility, and application-side configuration.

·       Maintain onboarding status, risks, decisions, blockers, metrics, and technical documentation in the organization’s ticketing and knowledge-management systems.

·       Create runbooks, data dictionaries, dashboard guides, alert specifications, validation evidence, and support documentation that enable sustainable ownership.

·       Provide demonstrations, knowledge transfer, and practical Splunk guidance to application teams so they can effectively use the content delivered for them.

·       Support continuous improvement of onboarding standards, intake forms, reusable templates, quality gates, and automation.

Required Qualifications

·       Experience using Splunk Enterprise or Splunk Cloud to search, analyze, visualize, and alert on machine data.

·       Hands-on proficiency with Search Processing Language, including filtering, aggregation, field extraction, lookups, time-based analysis, joins or alternatives, and performance-conscious search design.

·       Experience building production dashboards, alerts, reports, and scheduled searches for technical or business stakeholders.

·       Experience coordinating technical work across application owners, engineering teams, infrastructure teams, security teams, vendors, and project stakeholders.

·       Working knowledge of log collection and transport concepts such as agents or forwarders, syslog, REST APIs, databases, cloud services, queues or event streams, and structured data formats.

·       Ability to review sample events, recognize data-quality issues, identify useful fields, and explain logging gaps in clear business language.

·       Strong troubleshooting skills across applications, operating systems, networks, identity, permissions, and data pipelines.

·       Strong written and verbal communication skills, including the ability to lead discovery sessions, document decisions, explain technical constraints, and manage follow-up actions.

·       Ability to manage multiple concurrent onboarding efforts and content-development requests while maintaining accurate status and documentation.

·       Sound judgment when handling sensitive data and access-controlled information.

Preferred Qualifications

·       Experience with Splunk Enterprise Security, Splunk IT Service Intelligence, or comparable security and operational analytics platforms.

·       Experience with the Splunk Common Information Model, data models, accelerated searches, macros, event types, tags, and knowledge-object governance.

·       Experience with Splunk configuration concepts such as inputs, outputs, props, transforms, indexes, deployment apps, roles, and add-ons.

·       Familiarity with Linux and Windows logging, cloud and SaaS audit logs, Microsoft Azure, databases, identity platforms, network devices, and enterprise applications.

·       Experience designing security detections, fraud-monitoring content, compliance reporting, application-health dashboards, or operational key performance indicators.

·       Knowledge of software development or configuration-management practices, including source control, peer review, testing, release management, and change control.

·       Experience with scripting or automation using Python, PowerShell, shell scripting, REST APIs, or orchestration platforms.

·       Understanding of data protection, least privilege, data retention, audit logging, regulatory requirements, and secure handling of sensitive log data.

·       Experience in banking, financial services, healthcare, government, or another regulated environment.

·       Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Security+, or equivalent practical experience.

What Success Looks Like

·       Application teams understand the onboarding process, their responsibilities, and the decisions required from them.

·       New data sources move through discovery, implementation, validation, and production with clear status, ownership, and documented evidence.

·       Logs are complete, timely, searchable, normalized where appropriate, and suitable for the agreed security, compliance, operational, or business use cases.

·       Dashboards and alerts answer meaningful stakeholder questions and are actively used rather than delivered as one-time technical artifacts.

·       Alert logic is tested and tuned, with documented ownership and response expectations.

·       Blockers, sensitive-data concerns, unsupported requirements, and application-side dependencies are identified early and escalated constructively.

·       Reusable standards, templates, searches, and onboarding patterns reduce delivery time and improve consistency across applications.

·       Stakeholders receive clear metrics showing onboarding progress, content delivered, adoption, coverage gaps, and measurable outcomes.

Ideal Candidate Profile

You enjoy operating at the intersection of people, process, and technology. You can run a structured onboarding conversation with an application owner, inspect raw events with an engineer, write efficient Splunk searches, and turn the result into a dashboard or alert that solves a real problem. You are organized enough to keep many workstreams moving, curious enough to challenge incomplete logging, and practical enough to deliver useful outcomes without overengineering.

Supervisory Responsibilities

This position has no direct supervisory responsibilities but will coordinate work across multiple technical and business teams.

Applicant Guidance

Applicants should highlight examples where they coordinated a complex technical integration, improved the usefulness or quality of machine data, built Splunk content for a stakeholder, resolved an onboarding blocker, or translated an ambiguous business question into a measurable dashboard or alert. Final job level, minimum qualifications, work location, compensation, and standard employment language should be confirmed with Human Resources before publication.

 


Skills Required

  • Experience using Splunk Enterprise or Splunk Cloud to search, analyze, visualize, and alert on machine data
  • Hands-on proficiency with Search Processing Language, including filtering, aggregation, field extraction, lookups, time-based analysis, joins or alternatives, and performance-conscious search design
  • Experience building production dashboards, alerts, reports, and scheduled searches
  • Experience coordinating technical work across application owners, engineering, infrastructure, security, vendors, and project stakeholders
  • Working knowledge of log collection and transport using agents or forwarders, syslog, REST APIs, databases, cloud services, queues or event streams, and structured data formats
  • Ability to review sample events, identify data-quality issues and useful fields, and explain logging gaps clearly
  • Strong troubleshooting skills across applications, operating systems, networks, identity, permissions, and data pipelines
  • Strong written and verbal communication skills, including discovery sessions, technical documentation, and follow-up management
  • Ability to manage multiple concurrent onboarding and content-development efforts while maintaining accurate status and documentation
  • Sound judgment when handling sensitive data and access-controlled information
  • Experience with Splunk Enterprise Security, Splunk IT Service Intelligence, or comparable platforms
  • Experience with Splunk Common Information Model, data models, accelerated searches, macros, event types, tags, and knowledge-object governance
  • Experience with Splunk inputs, outputs, props, transforms, indexes, deployment apps, roles, and add-ons
  • Familiarity with Linux and Windows logging, cloud and SaaS audit logs, Microsoft Azure, databases, identity platforms, network devices, and enterprise applications
  • Experience designing security detections, fraud-monitoring content, compliance reporting, application-health dashboards, or operational KPIs
  • Knowledge of source control, peer review, testing, release management, and change control
  • Experience with Python, PowerShell, shell scripting, REST APIs, or orchestration platforms
  • Understanding of data protection, least privilege, data retention, audit logging, regulatory requirements, and secure handling of sensitive log data
  • Experience in banking, financial services, healthcare, government, or another regulated environment
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Security+, or equivalent practical experience

First Horizon Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about First Horizon Bank and has not been reviewed or approved by First Horizon Bank.

  • Retirement Support Retirement offerings include a 401(k) plan with company matching contributions up to 6% of pre-tax income, alongside FSA/HSA options and a defined benefit pension plan. Stock purchase and equity programs (including options and RSUs) also add to longer-term wealth-building opportunities for eligible employees.
  • Parental & Family Support Parental leave is available for childbirth, adoption, foster parenting, or surrogacy, and adoption reimbursement is included in the package. These family-building benefits broaden support beyond traditional maternity/paternity leave structures.
  • Wellbeing & Lifestyle Benefits Wellbeing support includes an internal wellness program, an employee assistance program, and access to a digital wellness platform. Group life insurance and disability coverage (including no-cost options) strengthen financial protection and day-to-day support.

First Horizon Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Memphis, TN
6,494 Employees
Year Founded: 1864

What We Do

When we opened our doors in 1864 on North Court Street in Memphis, we had a simple mission: to provide the best service to our customers, one opportunity at a time. In the 150 years that followed, our communities transformed and expanded. We’ve seen our business and banking in general grow and adapt to the changing needs of customers through the years. But one thing that will always remain constant is our commitment to financial integrity and to helping our customers take good care of their money.

Similar Jobs

Attio Logo Attio

Technical Support

Artificial Intelligence • Enterprise Web • Sales • Software
Remote or Hybrid
United States
140 Employees
85K-95K Annually

Mondelēz International Logo Mondelēz International

Operations Analyst

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
4 Locations
90000 Employees
97K-134K Annually

Wipfli Logo Wipfli

Quality Assurance Lead

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-131K Annually

Wipfli Logo Wipfli

Tax Senior Manager - Real Estate

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-192K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account