bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesTruezerotechSplunk Engineer-Core Certified Consultant/ ES Accreditation Required (R-00101)

Splunk Engineer-Core Certified Consultant/ ES Accreditation Required (R-00101)

Truezerotech · 100% Remote · Remote · Active · Lever

Job facts

FieldValue
CompanyTruezerotech
TitleSplunk Engineer-Core Certified Consultant/ ES Accreditation Required (R-00101)
Normalized title-
Department / teamEngineering & Architecture / Data/Analytics
LocationUnited States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS providerLever
Posted / first seen2025-11-13 / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Truezerotech.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Department jobsActive postings in Engineering & Architecture.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyTruezerotech
Sourcefd7b3fad-f07f-4438-ad90-754976718dfe
ATS providerLever

Description

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence. We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy: - Competitive salary, paid twice per month - Best in class medical coverage - 100% of medical premiums covered by True Zero - Company wide new business incentive programs - Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.) - 3 weeks of PTO starting + 11 Paid Holidays Annually - 401k Program with 100% company match on the first 4% - Monthly reimbursement of Cell Phone and Home Internet costs - Paternity/Maternity Leave - Investment in training and certifications to broaden and deepen your technical skills Job Responsibilities Implement RBA : Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts. Develop RBA components : Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores. Create dashboards and reports: Design custom dashboards to visualize risk scores and provide context for analysts. Correlate data: Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior. Build custom solutions : Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency. Content Development : Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments. Data : Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA. Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models. Preferred/Required Qualifications Core Certified Consultant is a requirement Technical Expertise : Deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL). Security Knowledge : Strong understanding of security operations, threat detection, incident response, and security frameworks (e.g., NIST RMF). Preferred relevant Splunk certifications are a plus such as: Splunk Core Certified Power User Splunk Enterprise Certified Admin Splunk Enterprise Certified Architect Splunk ES Scripting : Proficiency in scripting languages like Python, PowerShell, or Bash for automation and data analysis. Willingness to collaborate within an agile environment

Full job record

Job IDe51e0b54c722e04cc698cdf37598dc9c6798f21c
Org ID7db049a1-c308-497e-8ef0-4ae8ac5e3083
Source IDfd7b3fad-f07f-4438-ad90-754976718dfe
Board IDfd7b3fad-f07f-4438-ad90-754976718dfe
Providerlever
Provider Job Key196bc916-ff80-4c43-9715-c2ceb944f4f5
TitleSplunk Engineer-Core Certified Consultant/ ES Accreditation Required (R-00101)
Normalized Title
Statusactive
Activeyes
Location Text100% Remote
DepartmentEngineering & Architecture
TeamData/Analytics
Employment TypeFull-Time
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
City
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.lever.co/truezerotech/196bc916-ff80-4c43-9715-c2ceb944f4f5
Apply URLhttps://jobs.lever.co/truezerotech/196bc916-ff80-4c43-9715-c2ceb944f4f5/apply
First Seen At2026-05-29 07:10:49Z
Last Seen At2026-06-06 07:57:40Z
Last Checked At2026-06-06 07:57:40Z
Last Changed At2026-05-29 07:10:49Z
Inactive At
Source Posted At2025-11-13 04:28:28Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=truezerotech/date=2026-06-06/2026-06-06T07-57-39-812Z-1045bbe10c37aeac86194b1520ffe5fb98c894a8df85083f72f1b39f5b247cf1.json
Event Fields
{
  "content_hash": "28e1e8ac422853a6ad9eeff388e79a4e951429b790d5e6d40a4875720912e273",
  "source_hash": "d7fd93983aa04f81360318846617ffeed52bd63a760e8d85ea65e9c163103a17",
  "last_changed_at": "2026-05-29T07:10:49.241Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "100% Remote",
    "city": null,
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.9
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T07:57:40.714Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "100% Remote",
      "city": null,
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "Job Responsibilities  ",
      "content": "<li>Implement RBA<b>:</b>&nbsp;Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts.</li><li>Develop RBA components<b>:</b>&nbsp;Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores.</li><li>Create dashboards and reports:&nbsp;Design custom dashboards to visualize risk scores and provide context for analysts.</li><li>Correlate data:&nbsp;Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior.</li><li>Build custom solutions<b>:</b>&nbsp;Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency.</li><li>Content<b>&nbsp;</b>Development<b>:&nbsp;</b>Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments.</li><li>Data<b>: </b>Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA.</li><li>Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models.</li>"
    },
    {
      "text": "Preferred/Required Qualifications ",
      "content": "<li>Core Certified Consultant is a requirement </li><li>Technical<b>&nbsp;</b>Expertise<b>:</b>&nbsp;Deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL).</li><li>Security<b>&nbsp;</b>Knowledge<b>:</b>&nbsp;Strong understanding of security operations, threat detection, incident response, and security frameworks (e.g., NIST RMF).</li><li>Preferred relevant Splunk certifications are a plus such as:</li><li>Splunk Core Certified Power User</li><li>Splunk Enterprise Certified Admin</li><li>Splunk Enterprise Certified Architect</li><li>Splunk ES </li><li>Scripting<b>:</b>&nbsp;Proficiency in scripting languages like Python, PowerShell, or Bash for automation and data analysis.</li><li>Willingness to collaborate within an agile environment </li>"
    }
  ],
  "country": "US",
  "createdAt": 1763008108494,
  "updatedAt": null,
  "categories": {
    "team": "Data/Analytics",
    "location": "100% Remote",
    "commitment": "Full-Time",
    "department": "Engineering & Architecture",
    "allLocations": [
      "100% Remote"
    ]
  },
  "salaryRange": null,
  "workplaceType": "remote"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/e51e0b54c722e04cc698cdf37598dc9c6798f21c?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/7db049a1-c308-497e-8ef0-4ae8ac5e3083JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/fd7b3fad-f07f-4438-ad90-754976718dfeJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/e51e0b54c722e04cc698cdf37598dc9c6798f21c/eventsJSON