Splunk Engineer

Expert In Recruitment Solutions

  • Plano, TX
  • 30+ days ago

    Highlights

    The engineer will act as a trusted platform owner, ensuring Splunk availability, scalability, and reliability while partnering closely with Information Security, SOC, architecture, engineering, and operations teams. Strong expertise in Indexer clustering, search head clustering, Universal and heavy forwarder architectures, SmartStore/S3-compatible object storage, and SPL.

    Numbers & Facts

    LocationPlano, TX

    Description

    Title: Splunk Engineer
    Location: Hybrid/Onsite 3 days a week - Charlotte, NC or Plano, TX


    The engineer will act as a trusted platform owner, ensuring Splunk availability, scalability, and reliability while partnering closely with Information Security, SOC, architecture, engineering, and operations teams. This role will own end-to-end production support for a highly distributed Splunk Enterprise and Splunk Cloud environment.

    Responsibilities:
    • Ensure high availability, performance, and resiliency of the Splunk platform supporting security and operational use cases
    • Lead incident response, troubleshooting, root cause analysis (RCA), and service restoration for Splunk and Cribl platforms
    • Proactively identify risks, capacity constraints, and performance bottlenecks; implement preventive and tuning measures
    • Serve as a key technical enabler for Information Security and SOC teams, ensuring timely, accurate, and reliable ingestion of security logs
    • Onboard and normalize new data sources, supporting CIM compliance, field normalization, and SIEM best practices
    • Tune ingestion pipelines using props.conf and transforms.conf, index-time and search-time optimizations
    • Build and support dashboards, searches, and alerts that enable threat detection, investigations, and reporting
    • Administer and support the Cribl environment for data routing, filtering, enrichment, and cost optimization
    • Develop and maintain runbooks, SOPs, installation guides, and operational documentation
    • Adhere to change management, incident management, and SLA commitments using ITSM tools
    Requirements:
    • 5+ years of hands-on experience administering large-scale Splunk Enterprise or Splunk Cloud environments
    • Strong expertise in Indexer clustering, search head clustering, Universal and heavy forwarder architectures, SmartStore/S3-compatible object storage, and SPL
    • Deep experience with security log ingestion and SIEM use cases
    • Proven ability to lead production incidents, perform RCA, and drive preventive solutions
    • Strong Linux administration skills and experience managing Splunk configuration and apps
    • Experience working in 24x7 production environments with high availability expectations
    • Excellent written and verbal communication skills, with the ability to engage senior technical and business stakeholders
    Desired skills:
    • A production owner's mindset and deep technical credibility in Splunk and data pipelines
    • Ability to operate calmly and decisively during high-severity security and platform incidents
    • Splunk certifications such as Enterprise Admin or Enterprise Architect
    • Experience with Splunk Enterprise Security (ES) and SOAR (Phantom or equivalent)
    • Exposure to cloud logging and security architectures (AWS, Azure, GCP)
    • Knowledge of Red Hat Enterprise Linux and Windows Server administration
    • Experience with monitoring, APM, and event management tools
    • Strong understanding of security, network, system, and database operations
    • Ability to balance multiple priorities in a fast-paced, enterprise production environment

    Similar Jobs

    See more jobs