Confidential mandate
Splunk Cost-and-Detection Engineering Director — Cloud Marketplace
Planned Hiring / New
Splunk Cost-and-Detection Engineering Director mandate in Seattle, United States · Cloud Marketplace
A Seattle cloud marketplace needs an independent director to reduce uncontrolled Splunk economics while preserving high-value detection, proving the redesigned telemetry and content model within four months.
The mandate
Splunk ingest has doubled while several critical detections depend on incomplete or delayed data, making indiscriminate volume cuts unsafe. Duplicate cloud events, verbose development logs and poorly scoped indexes consume licence capacity, while expensive searches repeatedly scan fields that never affect analyst decisions. The defined problem is to value telemetry by security decision and redesign collection, storage and content without weakening evidenced coverage.
Deliverables are an ingest-cost baseline, telemetry utility map, routing architecture, retention tiers, detection dependency graph, optimised content pack and operating controls. Every proposed reduction must show affected detections, investigation uses, regulatory retention, alternative storage and rollback, while every retained source must have a named cost and security owner.
Milestone one on 9 October 2026 accepts cost and coverage facts; milestone two on 6 November delivers target routing and retention tiers; milestone three on 11 December concludes migration pilots; final acceptance on 15 January 2027 requires validated savings, regression tests and operator handover. Invoices follow those four accepted evidence packages.
Acceptance requires invoices to reconcile, priority behaviours to retain detection coverage, search performance to meet thresholds and internal engineers to onboard and retire sources unaided. A sampled source reduction must survive investigation replay, a high-cost detection must pass semantic comparison before and after optimisation, and forecast savings must reconcile to contracted pricing.
The client provides licence, index, search, detection and source data plus test environments, with SOC and application owners available to explain investigative use. The consultant cannot negotiate vendor contracts, suppress required logs or accept residual cyber risk; authorised employees implement production routing and approve retention changes.
Why this is external work
SOC teams fear losing visibility while platform owners treat ingest as a security demand. Neither owns the combined economics. Independent engineering can expose low-value volume and protect decision-critical data.
What you will own
- Reconcile Splunk licence, cloud infrastructure and engineering labour cost to sources, indexes, searches and business owners.
- Grade telemetry by detection dependency, investigation value, compliance need, field reliability, alternative source and uniqueness.
- Design filtering, aggregation, routing and retention without destroying forensic context, temporal sequence or rare-event visibility.
- Refactor searches and data models for accuracy, latency and compute efficiency.
- Regression-test priority detections before and after every source change.
- Establish source onboarding and retirement gates with cost, detection, investigation, compliance and platform owners.
- Transfer dashboards, versioned code, routing decisions, regression evidence and cost governance through client-run changes.
Candidate qualifications
- Directed Splunk or comparable SIEM engineering at multi-terabyte daily scale with material licence accountability.
- Can evidence material SIEM cost reduction without losing validated detection coverage or investigation context.
- Built telemetry filtering, routing, tiering and search optimisation across large cloud and application estates.
- Mapped detections and investigations to specific source-field dependencies.
- Reconciled technical usage to licence, compute, storage, search and engineering economics under contracted pricing.
- Handed versioned detection content, routing controls, regression tests and FinOps governance to internal teams after independent operation.
Non-negotiables
- Available across the sixteen-week delivery calendar.
- Independent of Splunk resellers and competing SIEM vendors.
- Will accept savings and detection regression tests together.
- Has production SIEM engineering authority beyond dashboard administration.
- 49 words maximum. Which Splunk source have you reduced without harming decision-grade visibility?
- 49 words maximum. Describe a costly search whose rewrite preserved detection semantics.
- 49 words maximum. What regression evidence must precede retiring a telemetry source?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.