Job Description
RESPONSIBILITIES :
Splunk Infrastructure & Administration
- Design, deploy, and maintain enterprise solutions and components for Splunk Cloud and on premises environments including Search Heads, Indexers, Forwarders and Deployment Servers
- Manage Splunk high availability configurations
- Deploy, configure, and maintain Splunk Connect for Syslog (SC4S)
- Perform capacity planning, performance tuning, and resource optimization
- Implement and maintain data retention policies and index management strategies
- Oversee Splunk upgrades, patches, and maintenance activities
Data Integration & Management
Configure and manage universal forwarders, heavy forwarders, and data inputs from diverse sourcesDevelop and maintain data parsing, field extractions, and data modelsCreate and optimize indexes, source types, and data routing configurationsImplement data quality controls and validation processesDesign efficient search strategies and query optimizationDevelopment & Automation
Develop custom Splunk applications, dashboards, and visualizationsCreate and maintain complex SPL (Search Processing Language) queries and reportsBuild automated monitoring solutions and alerting mechanismsDevelop Python scripts and REST API integrations for Splunk automationImplement Infrastructure as Code (IaC) practices for Splunk deploymentsSecurity & Compliance
Design and implement security information and event management (SIEM) solutionsDevelop security monitoring use cases and threat detection scenariosCreate compliance reporting and audit trail mechanismsImplement role-based access controls and data classification policiesSupport incident response and forensic investigationsCollaboration & Leadership
Mentor team members and provide technical guidanceCollaborate with cross-functional teamsLead technical architecture reviews and design sessionsParticipate in on-call rotation and provide escalation supportDocument processes, procedures, and best practicesEDUCATIONAL REQUIREMENTS :
Bachelor's degree in computer science, Information Systems, or equivalent combination of education and experienceRelevant Security CertificationsExperience Required
A minimum of 10 years of experience.QUALIFICATIONS, KNOWLEDGE, SKILLS & ABILITIES :
7+ years of hands-on Splunk experience including administration and developmentSplunk certifications required : Splunk Core Certified Admin, Splunk Core Certified Power User, Splunk Cloud Certified AdminPreferred certifications : Splunk Enterprise Security Certified Admin, Splunk IT Service IntelligenceProficiency in SPL (Search Processing Language) and advanced search techniquesExperience with Splunk Enterprise Security (ES), IT Service Intelligence (ITSI), or other Splunk premium applicationsStrong knowledge of Linux / Unix systems administrationScripting experience in Python, Shell, PowerShell, or similar languagesUnderstanding of networking protocols, log formats, and data sources (syslog, JSON, XML, etc.)Infrastructure & Tools
Experience with virtualization platforms (VMware, Hyper-V) and cloud environments (AWS, Azure, GCP)Knowledge of configuration management tools (Terraform, Ansible, Puppet, Chef)Familiarity with containerization technologies (Docker, Kubernetes)Experience with load balancers, firewalls, and network security devicesUnderstanding of database systems and SQLSecurity & Compliance
Knowledge of security frameworks (NIST, ISO 27001, PCI-DSS, SOX)Experience with threat hunting and incident response proceduresUnderstanding of common attack vectors and security monitoring best practicesFamiliarity with compliance reporting requirementsPreferred Qualifications
Bachelor's degree in Computer Science, Information Technology, or related fieldExperience with additional SIEM platformsKnowledge of machine learning and statistical analysis techniquesExperience with DevOps practices and CI / CD pipelinesIndustry certifications such as CISSP, GCIH, or equivalentTechnical Environment
Multi-terabyte daily data ingestionHigh-availability clustered deploymentsIntegration with enterprise security tools and business applicationsHybrid cloud and on-premises infrastructureGeneral Skills Include
Strong critical thinking and analytical skillsAbility to approach problem solving in a constructive and collaborative way that does not require absolute security.The ability to communicate complicated technical issues and risks to programmers, network engineers and managers.Strong leadership, project, and team-building skillsExceptional communication skills with diverse audiences; the ability to be an infrastructure security subject matter expert who can explain relevant topics to general audiences
Skills Required
VMware, Unix, Chef, Sql, Rest Api, Iso 27001, Gcp, Docker, Linux, Terraform, Ansible, nist, Splunk, Sox, Puppet, Azure, Python, Kubernetes, Aws