Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Splunk Engineer

RIT Solutions

Splunk Engineer

Location: Hybrid/ Onsite 3 days a week - Charlotte, NC or Plano, TX

The engineer will act as a trusted platform owner, ensuring Splunk availability, scalability, and reliability while partnering closely with Information Security, SOC, architecture, engineering, and operations teams. This role will own end-to-end production support for a highly distributed Splunk Enterprise and Splunk Cloud environment.

Responsibilities:
  • Ensure high availability, performance, and resiliency of the Splunk platform supporting security and operational use cases
  • Lead incident response, troubleshooting, root cause analysis (RCA), and service restoration for Splunk and Cribl platforms
  • Proactively identify risks, capacity constraints, and performance bottlenecks; implement preventive and tuning measures
  • Serve as a key technical enabler for Information Security and SOC teams, ensuring timely, accurate, and reliable ingestion of security logs
  • Onboard and normalize new data sources, supporting CIM compliance, field normalization, and SIEM best practices
  • Tune ingestion pipelines using props.conf and transforms.conf, index-time and search-time optimizations
  • Build and support dashboards, searches, and alerts that enable threat detection, investigations, and reporting
  • Administer and support the Cribl environment for data routing, filtering, enrichment, and cost optimization
  • Develop and maintain runbooks, SOPs, installation guides, and operational documentation
  • Adhere to change management, incident management, and SLA commitments using ITSM tools
Requirements:
  • 5+ years of hands-on experience administering large-scale Splunk Enterprise or Splunk Cloud environments
  • Strong expertise in Indexer clustering, search head clustering, Universal and heavy forwarder architectures, SmartStore/S3-compatible object storage, and SPL
  • Deep experience with security log ingestion and SIEM use cases
  • Proven ability to lead production incidents, perform RCA, and drive preventive solutions
  • Strong Linux administration skills and experience managing Splunk configuration and apps
  • Experience working in 24x7 production environments with high availability expectations
  • Excellent written and verbal communication skills, with the ability to engage senior technical and business stakeholders
Desired skills:
  • A production owner's mindset and deep technical credibility in Splunk and data pipelines
  • Ability to operate calmly and decisively during high-severity security and platform incidents
  • Splunk certifications such as Enterprise Admin or Enterprise Architect
  • Experience with Splunk Enterprise Security (ES) and SOAR (Phantom or equivalent)
  • Exposure to cloud logging and security architectures (AWS, Azure, GCP)
  • Knowledge of Red Hat Enterprise Linux and Windows Server administration
  • Experience with monitoring, APM, and event management tools
  • Strong understanding of security, network, system, and database operations
  • Ability to balance multiple priorities in a fast-paced, enterprise production environment
Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Splunk Engineer. Be the first to apply!