Job Description
We are seeking a highly skilled Splunk to Elastic Migration Engineer to lead and execute end‑to‑end SIEM modernization initiatives. This role is responsible for designing and implementing Elastic deployments using the Elastic Cloud on Kubernetes (ECK) model, migrating legacy Splunk knowledge objects, detections, and data pipelines, and ensuring operational readiness through cutover validation and workflow integration.
The ideal candidate has deep hands‑on experience with SIEM engineering, detection engineering, Elastic Stack architecture, and security operations workflows—particularly within enterprise or federal environments.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
* 5+ years' experience in SIEM engineering or security operations
* Hands‑on experience with Elastic Stack (Elasticsearch, Kibana, Elastic Security)
* Proven experience migrating from Splunk to Elastic or similar SIEM platforms
* Strong understanding of:
SIEM data models and schemas
* Elastic Common Schema (ECS)
* Detection engineering and alert tuning
* Experience with Kubernetes and the ECK deployment model
* Strong scripting or automation skills (Python, Bash, etc.)
Nice to Have Skills & Experience
Experience supporting DoD, federal, or highly regulated environments
Familiarity with MITRE ATT&CK–based detection frameworks
Experience integrating SIEM tools with SOAR platforms
Elastic Certified Engineer or Analyst certifications
Splunk administration or migration background
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.