UnitedHealth Group is a global organization that delivers care aided by technology to help millions of people live healthier lives. They are seeking a highly experienced Principal Security Engineer to lead Splunk engineering and onboarding efforts across acquired entities, serving as the Splunk Subject Matter Expert (SME) and ensuring scalable log ingestion and operational excellence. This role involves collaborating with cross-functional teams and acting as a mentor to security engineers and analysts.
Responsibilities:
- Serve as the primary Splunk SME, providing architecture guidance, troubleshooting support, and strategic direction
- Design, build, and optimize enterprise-scale Splunk infrastructure (indexers, search heads, forwarders, clustering, and cloud/hybrid deployments)
- Define standards, best practices, and governance for Splunk usage, data onboarding, and content development
- Lead performance tuning, capacity planning, and cost optimization initiatives
- Lead onboarding of logs from newly acquired entities into Splunk, including:
- Log source identification and prioritization
- Data ingestion architecture design
- Field extraction, parsing, and normalization
- Partner with acquisition teams, IT, and security stakeholders to ensure timely and complete visibility
- Develop repeatable onboarding playbooks and integration frameworks for rapid scaling
- Ensure alignment with enterprise security use cases, compliance requirements, and detection strategies
- Implement and maintain secure, reliable log pipelines across cloud, on-prem, and SaaS environments
- Ensure high availability and resilience of Splunk services
- Oversee data quality, integrity, and retention policies
- Support SOC operations by enabling efficient search, dashboards, alerts, and detection content
- Act as a technical leader and mentor to security engineers and analysts
- Collaborate with cross-functional teams (Cloud, Infrastructure, DevOps, Security Operations)
- Influence and drive adoption of standardized logging and monitoring practices
- Communicate technical strategies and risks to senior leadership
Requirements:
- 4+ years of experience in security engineering, SIEM, or data platform engineering
- 3+ years of experience with Splunk Enterprise and/or Splunk Cloud
- Experience managing and scaling Splunk infrastructure
- Solid experience onboarding logs across: Cloud platforms (AWS, Azure, GCP), Network/security devices, Endpoints, SaaS, and custom applications, Data ingestion (UF/HF, APIs, syslog, cloud-native integrations), Parsing, CIM normalization, and knowledge objects
- Proven solid scripting skills (Python, Bash, or similar)
- Experience with Security Operations (SOC) and detection engineering
- Experience supporting M&A / acquisition integrations
- Knowledge of SOAR platforms and automation
- Familiarity with frameworks such as MITRE ATT&CK