Splunk Architect Lead
ECS Limited
Everforth ECS is seeking a Splunk Architect Lead to work in our Portland, OR office. Please Note: This position is contingent upon contract award.
The Splunk Architect and Lead is responsible for defining, guiding, and overseeing the architecture, implementation, optimization, and governance of Splunk capabilities that support cybersecurity monitoring, threat detection, incident response, reporting, and enterprise security operations. This role provides technical leadership for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, and related integrations across complex operational environments.The ideal candidate combines deep Splunk architecture expertise, hands-on engineering experience, security operations knowledge, and leadership ability to guide engineers, analysts, stakeholders, and vendors. This role establishes scalable designs, enforces technical standards, ensures platform reliability, and translates mission and SOC requirements into secure, maintainable, and operationally effective Splunk solutions.
Key Responsibilities Splunk Architecture & Strategy
- Define and maintain the target Splunk architecture, including indexer clusters, search head clusters, deployment servers, heavy forwarders, universal forwarders, apps, add-ons, integrations, storage, and high-availability components.
- Develop technical roadmaps, architecture recommendations, implementation plans, and modernization strategies for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or hybrid Splunk environments.
- Ensure Splunk architecture supports SOC operations, security monitoring, incident response, compliance reporting, data retention, scalability, resilience, and performance requirements.
- Assess current-state capabilities, identify architectural gaps, and recommend improvements aligned to program priorities, operational needs, and cybersecurity best practices.
- Serve as the technical lead for Splunk engineering activities, providing direction, review, and mentorship to Splunk engineers, security engineers, analysts, and other technical contributors.
- Establish and enforce Splunk standards for index naming, sourcetypes, field extractions, Common Information Model alignment, knowledge objects, access controls, app deployment, configuration management, and change control.
- Review major design decisions, configuration changes, content deployments, and integration approaches for technical soundness, maintainability, security, and operational impact.
- Coordinate Splunk engineering priorities, assign technical work as needed, and ensure deliverables are completed accurately, consistently, and on schedule.
- Lead design efforts for platform performance, capacity, storage, retention, data lifecycle management, search concurrency, licensing, disaster recovery, backup, and high availability.
- Oversee platform health monitoring, performance tuning, system optimization, upgrade planning, patching strategies, and long-term maintenance planning.
- Guide troubleshooting of complex issues involving ingestion delays, parsing problems, skipped or dropped data, search performance, data model acceleration, app conflicts, and infrastructure dependencies.
- Partner with infrastructure, cloud, network, identity, endpoint, and system administration teams to ensure Splunk architecture integrates securely and reliably with the broader environment.
- Define data onboarding architecture and integration patterns for security, infrastructure, cloud, endpoint, network, identity, application, vulnerability, and operational data sources.
- Oversee normalization, parsing, field extraction, data routing, index design, retention settings, source coverage, and Splunk Common Information Model implementation.
- Prioritize data source onboarding based on mission value, SOC use cases, detection requirements, compliance needs, and platform capacity constraints.
- Ensure integrations with EDR, NDR, firewalls, IDS/IPS, proxy, DNS, cloud platforms, identity providers, ticketing systems, SOAR platforms, and case management tools are secure, reliable, and supportable.
- Translate SOC, threat hunting, threat intelligence, incident response, and leadership requirements into Splunk architecture, data, dashboard, reporting, and detection engineering capabilities.
- Provide technical guidance for correlation searches, notable event rules, dashboards, reports, risk-based alerting, data models, content packs, and security monitoring use cases.
- Support detection tuning, alert fidelity improvement, false-positive reduction, source coverage analysis, and monitoring gap remediation in coordination with SOC leadership and analysts.
- Ensure Splunk content and data capabilities support timely triage, investigation, evidence retrieval, event reconstruction, and operational reporting.
- Lead or oversee implementation activities for Splunk platform components, integrations, apps, add-ons, dashboards, reports, alerts, and security content.
- Validate engineering work products, test plans, deployment packages, configuration changes, and operational procedures before release into production environments.
- Ensure Splunk changes follow approved change management, configuration management, testing, documentation, and rollback processes.
- Coordinate with vendors, product support, and external technical teams to resolve complex issues and evaluate new capabilities.
- Act as the primary technical point of contact for Splunk architecture, platform strategy, implementation risks, technical dependencies, and capability planning.
- Brief program leadership, SOC leadership, technical teams, and stakeholders on Splunk status, risks, roadmap items, architectural decisions, and recommended investments.
- Translate complex Splunk platform issues, data coverage gaps, and technical tradeoffs into clear operational and business language.
- Support planning, estimation, schedule coordination, status reporting, and prioritization for Splunk-related initiatives.
- Develop and maintain architecture diagrams, engineering standards, design documents, runbooks, operational procedures, troubleshooting guides, and technical decision records.
- Maintain governance for knowledge object management, role-based access, app lifecycle management, source onboarding, dashboard standards, and detection content lifecycle processes.
- Evaluate emerging Splunk features, apps, add-ons, integrations, automation approaches, and security analytics practices to improve reliability, efficiency, and mission value.
- Mentor technical staff and promote consistent Splunk engineering practices, SPL development standards, data quality expectations, and operational discipline.
- U.S. Citizenship with ability to obtain and maintain a DOE "L" clearance after start.
- 7+ years of experience in cybersecurity engineering, SIEM architecture, security operations, infrastructure engineering, or related technical roles.
- 5+ years of hands-on Splunk administration, engineering, implementation, or architecture experience in enterprise, mission-critical, or security operations environments.
- Proven experience designing, leading, or supporting complex Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or distributed Splunk environments.
- Strong understanding of Splunk architecture, including indexers, search heads, deployment servers, forwarders, apps, add-ons, indexes, sourcetypes, knowledge objects, permissions, data models, and licensing.
- Demonstrated experience with data onboarding, parsing, field extraction, normalization, Common Information Model alignment, dashboards, reports, correlation searches, and SPL development.
- Experience leading technical teams, reviewing engineering work products, establishing standards, and coordinating complex implementation or optimization activities.
- Understanding of SOC operations, incident response, threat hunting, detection engineering, cybersecurity data sources, and security monitoring use cases.
- Strong written and verbal communication skills, including the ability to brief technical and non-technical stakeholders on architecture, risks, priorities, and recommendations.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Splunk Architect Lead in Portland, OR vacancy
- ...Position: Splunk Architect or Senior Engineer Location - Seattle, WA - Hybrid Duration: 12+ Months Contract Responsibilities & Qualifications: Experienced in using SPLUNK created Visualizations to get the value out of data Experience in administration...SuggestedContract work
- WorkSource Oregon is seeking a Bilingual Mandarin Lab Supervisor for their Beaverton, Oregon location. This role involves team leadership, ensuring lab compliance with safety protocols, and translating technical protocols for effective communication. The ideal candidate...Suggested
- EmergencyMD is seeking a 911 Emergency Communications Dispatch Supervisor in Vancouver, WA. This role involves supervising call takers and dispatching for police, fire, and medical services. Candidates should possess strong leadership, decision-making, and communication...Suggested
- Levy Restaurants is seeking a Concessions Supervisor in Portland, Oregon, to oversee assigned concession locations and ensure compliance with service standards. The ideal candidate will have supervisory experience in a fast-paced environment and be ready to create memorable...Suggested
- LCA Lab. Corp. of America is looking for a Lab Supervisor at the Halsey Lab in Portland, OR. In this role, you will supervise daily lab operations and serve as a technical resource for high volume areas such as Chemistry and Hematology. The ideal candidate will hold a Bachelor...Suggested
- Honey Bucket is looking for a Route Supervisor to lead our team of route drivers in Tualatin, Oregon. This role is vital for ensuring that we provide top-tier portable sanitation services while mentoring and developing our staff. As a Route Supervisor, you will oversee...
- Honeybucket is seeking a Route Supervisor to lead our team of Route Drivers in Tualatin, Oregon. The role is crucial in fostering quality service and mentoring employees, while ensuring operational efficiency and customer satisfaction. The ideal candidate will possess...
$37 - $40 per hour
Columbia River Veterinary Specialists is hiring an Emergency Technician Supervisor (Dayshift) in Vancouver, WA. This role involves supervising technical staff and managing patient care, while also ensuring effective medical record keeping and handling financial processes...Hourly payDay shift$18.77 - $20.5 per hour
...seeking a full-time Store Supervisor to utilize management and customer service skills. In this role, you will oversee store operations, lead a team, and ensure excellent service. The position offers competitive pay of $18.77 - $20.50 per hour, alongside benefits like...Hourly payFull time- The Springs Living in Lake Oswego, Oregon, is seeking a Housekeeping Lead responsible for supervising the housekeeping team and maintaining high standards of cleanliness. In this role, you'll oversee inventory management, scheduling, and ensure exceptional service to residents...
- ...Parts Company is seeking a Production Supervisor in Portland, Oregon. This role specializes in managing production activities and leading a team to achieve quality targets. The ideal candidate should have 5-10 years of relevant experience and a high school diploma or GED...
$21 per hour
...We are hiring immediately for full time SUPERVISOR, FRONT OF HOUSE LEAD positions. Location : Delta PDX - 7000 NE Airport Way, Suite 211, Portland, OR 97218. Note: online applications accepted only . Schedule : Full time schedule. Sunday through Wednesday...Hourly payFull timePart timeLocal areaImmediate startRemote workWorldwideFlexible hours$21 per hour
...Eurest We are hiring immediately for full time SUPERVISOR, FRONT OF HOUSE LEAD positions. Location : Delta PDX - 7000 NE Airport Way, Suite 211, Portland, OR 97218. Note: online applications accepted only . Schedule : Full time schedule. Sunday through...Hourly payFull timePart timeLocal areaImmediate startRemote workWorldwideFlexible hours- Dormont Manufacturing Co is looking for a Group Lead to oversee production activities in Tualatin, Oregon. This role involves supervising personnel, ensuring quality standards, and assisting in training and production planning. Candidates should have a strong understanding...Afternoon shift
$24 - $32.5 per hour
Speedproalpharetta is seeking a Production Manager in Beaverton, Oregon to manage the production of high-quality printed graphics. The ideal candidate will have 1-3 years of experience with large-format printing equipment and proficiency in Adobe Creative Suite. Responsibilities...Hourly pay$95k - $105k
..., OR. In this full-time role, you will supervise underground drilling operations and ensure compliance with safety standards while leading crew training initiatives. Candidates should have 5+ years of hands-on experience in underground drilling and strong communication...Full time- The State of Washington is looking for a Heavy Equipment Mechanic 4 Supervisor to oversee maintenance operations across the Southwest Region. This role includes supervising a team of mechanics and ensuring compliance with safety and regulatory standards. The ideal candidate...Flexible hours
$61.25 per hour
The M. A. Mortenson Company is seeking a Carpenter Foreman in Vancouver, WA. This position involves overseeing carpentry crews, ensuring projects are executed according to specifications, and performing various carpentry tasks. Applicants should have a high school diploma...Hourly pay- Kroger in Gresham, Oregon is seeking an Assistant Manager to oversee department operations and ensure excellent customer service. The ideal candidate will have a BA/BS in business or related field, with significant retail experience. You will model the Company's core values...Flexible hours
$100k - $115k
...Act-On Software is seeking a Marketing Campaign Manager in Portland, Oregon. The role involves developing and executing integrated lead generation campaigns that drive customer acquisition and revenue. The ideal candidate will have over 5 years of experience within a...- ...skills. We are committed to being America's best first job. Let's talk. Make your move. See a day in the life of a Guest Experience Lead at McDonald's Requirements: We believe in letting you do you. If you're looking for a part-time job that supports your full-time...Full timePart time
- ...access your pay when you need it! (CA locations exempt) ~ Opportunities for growth ~ And much more! In the role of Catering Lead, you will work in a fast-paced environment to ensure that our guests receive great food and service. You will be responsible to...Hourly payDaily paidLocal areaMonday to FridayFlexible hoursDay shiftEarly shift
- ...Shipping Lead Job Category: Shipping Requisition Number: SHIPP002740 Description Duties and Responsibilities Primary Maintains an atmosphere of enthusiasm Comprehends and ensures compliance with company SQF policies pertaining to the dock area...Shift work
$20 - $24 per hour
...Creative and caring people, this job is for you! The Holgate Center is seeking a Lead Med Tech for our senior living community in Portland, serving 100+ residents in our assisted living apartments. Holgate Center (HC) strives to provide a positive work environment...Full timeFlexible hoursShift work- ...Position Overview: We are seeking a dedicated and proactive Shift Lead to join our team. This role is essential in ensuring that shifts run smoothly and efficiently, particularly in the absence of management. The ideal candidate will exemplify strong leadership qualities...Full timeShift workDay shift
- ...divh2Front Desk Lead Associate/h2pWe are looking for a positive Front Desk Lead Associate to join our team! At the Front Desk, you are the face of our business and set the tone for creating exceptional experiences for all our members. You will greet members, answer questions...
- ...Security Lead New Seasons Market began in 2000 as a neighborhood market, a place where local communities can come together to connect with where their food comes from. A friendly, inviting place that honors its region's farmers, ranchers, growers and makers. Today...Full timeTemporary workPart timeWork at officeLocal areaShift work
$157k - $281.93k
...A leading design software company is seeking a Senior Manager of Content Strategy in Portland, Oregon. This role focuses on leading a new team to define the content strategy for transformative AI-powered experiences. Candidates should have over 12 years in content strategy...- Company Description JPC LLC is a Franchise with Domino's Pizza looking to provide opportunity to new team members who are looking for the FUN job! Develop skills and grow fast within our organization. Opportunities are limitless with Domino's! Job Description ...Hourly payFull timeWork experience placementFlexible hoursShift workDay shift
- ...Front Desk Lead Associate We are looking for a positive Front Desk Lead Associate to join our team! At the Front Desk, you are the face of our business and set the tone for creating exceptional experiences for all our members. You will greet members, answer questions...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Splunk Architect Lead. Be the first to apply!

