Obeikan Investment Group

Splunk SIEM Engineer (RE)

Obeikan Investment Group  •  Riyadh, SA (Onsite)  •  2 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Innovative Solutions (IS) is a leading Cybersecurity company established in 2003, with its headquarters in Riyadh and additional offices in Al Khobar, Jeddah, Dubai, and Abu Dhabi. We specialize in delivering Comprehensive Cybersecurity Solutions and Services encompassing Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed Security Services.

Our mission is "Delivering secure and intelligent digital services that empower organizations"

We are seeking a Splunk SIEM Engineer to provide hands-on support, administration, optimization, and continuous enhancement of the Splunk environment. The role is responsible for ensuring the reliability, performance, and effectiveness of Splunk services while supporting security monitoring and operational use cases.

Responsibilities

• Perform indexing and data ingestion activities, including ingesting, parsing, and indexing log sources to ensure accurate, consistent, and searchable data.

• Identify and resolve ingestion-related issues such as parsing errors, timestamp extraction problems, event breaking, line breaking, and truncation.

• Monitor Splunk system performance and optimize queries, dashboards, index configurations, and data retention policies to meet defined SLAs.

• Review existing Splunk architecture and indexing capacity, and provide recommendations to improve scalability, reliability, and cost efficiency.

• Design, configure, and maintain alerts, correlation searches, dashboards, and reports based on operational and user requirements.

• Diagnose system issues and failures, conduct root-cause analysis, implement remediation actions, and perform follow-up verification.

• Ensure the Splunk environment follows security best practices and applicable compliance requirements, including access controls and auditing.

• Maintain up-to-date technical documentation, runbooks, and user guides.

• Deliver knowledge-transfer sessions to operations and engineering teams.

• Maintain a comprehensive inventory of Splunk content, including dashboards, saved searches, alerts, correlation searches, lookup tables, macros, knowledge objects, and use cases.

• Classify Splunk content by owner, business function, usage frequency, and last modified date.

• Provide end-to-end SIEM capabilities, including detection, alerting, and response for security threats and operational risks.

• Develop and maintain detection logic, required data sources, alert severity and thresholds, dashboards, runbooks/playbooks, and SLA-aligned acceptance criteria.

• Review connected data sources to assess data quality and completeness, and report findings with onboarding readiness recommendations.

• Provide a Splunk maturity roadmap aligned with the organization's current maturity level.

• Assess log quality for high-volume sources and recommend source optimization to maximize value and reduce cost.

• Review existing Splunk content and recommend consolidation, optimization, or creation of new use cases.

• Provide hands-on operational support and assist in removing technical or operational blockers.

• Develop standardized workflows and guidance for building, validating, and operationalizing new Splunk use cases.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 3–5 years of relevant experience in Splunk administration, engineering, or SIEM operations.
  • Strong understanding of Splunk architecture and data flow concepts.
  • Solid knowledge of security operations and SIEM principles.
  • Ability to analyze system performance and identify optimization opportunities.
  • Strong analytical and problem-solving skills for diagnosing system and data issues.
  • Good understanding of security best practices and compliance concepts.
  • Ability to work with technical documentation and structured operational processes.
  • Strong communication skills for coordination with technical and operational teams.
  • Familiarity with AI tools and technologies.
Obeikan Investment Group

About Obeikan Investment Group

Let’s Shape the Future Together ..

Since 1982, Obeikan Investment Group has built thriving businesses in multiple channels. This is what four decades of experience have taught us:

- Businesses that stay on conventional paths will ultimately be overtaken by more agile competitors.

- Incremental steps aren’t enough to maintain market leadership, so thinking big is essential.

- A successful future takes ongoing, radical, all-hands-on-deck innovation.

- And innovation isn’t a project with an end date—it’s an embedded mindset.

Innovation is at the core of everything we do at Obeikan. The world of business has changed and the future is no longer an extension of today; continual re-invention is a now pre-requisite for success. To compete, we’re perpetually re-engineering our processes, products and organisation to do more and to do better—executing faster, more reliably, more productively and more profitably.

Today, the catalyst of innovation is digital transformation. It’s enabled us to perform at the highest level, and now we are making the same possibilities available to our clients. Obeikan’s digital technologies are a bridge to full membership in the digital economy. As a leader in digital transformation, we’re empowering our customers to refine their operations, amplify their impact, and sharpen their competitiveness.

We’re passionate about sharing our knowledge to change our world for the better. We give our best every day to help help build an increasingly dynamic economy and society, and to partner for collective wins. Through collaboration with Obeikan, clients can also create new paths to success, revitalise business operations and relationships, and accelerate value creation.

Are you ready? Let’s shape the future together.

Industry
Manufacturing & Production
Company Size
501-1,000 employees
Headquarters
Riyadh, SA
Year Founded
1982
Website
com.sa
Social Media