← Back to jobs

Senior Splunk and DLP Security Engineer

Skills

dlpsplunk

Description

Job Overview

We are seeking an experienced Senior Splunk and DLP Security Engineer to enhance and optimise DLP monitoring, alerting and reporting capabilities across Splunk and the wider DLP toolset.

The successful candidate will have strong hands-on experience developing advanced Splunk searches, correlating multiple DLP data sources, refining detection logic and building actionable dashboards and alerts. You will work independently to improve monitoring effectiveness, reduce false positives and establish sustainable reporting and operational processes.

You will also support junior analysts, share technical knowledge and ensure the team has clear documentation and runbooks to maintain and develop the enhanced capabilities.

Key Responsibilities
  • Develop and optimise advanced Splunk searches using SPL, including multi-index correlation, drilldowns and alert development.
  • Analyse DLP-related indexes and integrate multiple DLP data sources to create joined views of user activity, incidents and control outcomes.
  • Build and enhance Splunk dashboards to support operational monitoring and management reporting.
  • Review and tune detection logic to reduce false positives and convert high-volume monitoring data into targeted, actionable alerts.
  • Develop and refine DLP correlation searches and detection use cases to improve monitoring effectiveness.
  • Create clear documentation covering searches, dashboards, alert logic, correlation use cases and operational processes.
  • Produce and maintain runbooks to support consistent operations and knowledge retention within the internal team.
  • Work independently to identify monitoring improvements and deliver practical enhancements across the DLP capability.
  • Support junior analysts through technical guidance, knowledge sharing and knowledge transfer.
  • Establish a sustainable approach to DLP reporting, alerting and ongoing monitoring improvements.
Essential Skills and Experience
  • Strong hands-on Splunk engineering experience.
  • Advanced SPL skills, including complex searches and multi-index correlation.
  • Experience building Splunk dashboards, drilldowns and alerts.
  • Practical experience working with DLP-related indexes and data sources.
  • Ability to correlate multiple DLP data sources into meaningful views of user activity, incidents and control outcomes.
  • Experience tuning detection logic and reducing false-positive alerts.
  • Ability to translate high-volume monitoring data into targeted, actionable security alerts.
  • Experience developing operational dashboards and management reporting.
  • Strong documentation skills, including search documentation, operational procedures and runbooks.
  • Ability to work independently, manage technical improvements and transfer knowledge to junior analysts.
Expected Deliverables
  • Improved DLP monitoring dashboards and management reports.
  • Refined detection alerts and DLP correlation use cases.
  • Better correlation of user activity, incidents and control outcomes across multiple data sources.
  • Reduced false positives and more actionable alerts.
  • Documented Splunk searches, processes and operational runbooks.
  • A sustainable reporting and monitoring capability that the internal team can maintain.
Working Arrangements
  • London, UK.
  • Hybrid working, with three days per week onsite at the client’s office.

Get similar jobs in United Kingdom by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more Security Engineer jobs in United Kingdom.

Finding similar jobs…