
Develop and maintain correlation searches and dashboards on the Splunk ES platform. Collaborate with stakeholders to gather requirements and translate threat scenarios into actionable detection use cases. Design, develop, tune, and continuously improve Splunk ES correlation searches aligned with MITRE ATT&CK techniques and Euroclear threat models. Validate detections through structured testing, evidence collection, and adversary simulation tooling. Perform false-positive analysis, baseline creation, and high-fidelity tuning to maintain actionable and reliable detection signals. Maintain clear, structured documentation for detection logic, testing procedures, ATT&CK mapping, and operational deployment guidelines. Conduct coverage gap assessments, maintain the detection inventory, and contribute to ATT&CK-based coverage reporting and maturity tracking. Perform peer reviews of detection content to ensure quality, consistency, and adherence to detection engineering standards. Implement and optimize Splunk ES features such as correlation search patterns, notable events, and risk-based alerting (RBA). Work closely with the log onboarding team to ensure high-quality telemetry, correct field extractions, CIM compliance, and accurate Data Model mapping. Identify and implement improvements to detection workflows, telemetry quality, and the overall detection engineering lifecycle.