Splunk Engineer
fuse
Meade, KS, United States
2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Bash Shell
Computer Networks
Python (Programming Language)
Linux System Administration
Nagios
NetFlow
Performance Tuning
Security Information and Event Management
Syslog
Data Logging
Scripting
+4 more
Data Ingestion
Containerization
Splunk
Vulnerability Analysis
Job description
The Splunk Engineer is responsible for the design, implementation, optimization, and sustainment of enterprise logging, monitoring, and security analytics solutions. This role ensures Splunk environments meet availability, performance, compliance, and audit requirements ., * Architect, deploy, and maintain enterprise Splunk environments, including indexers, search heads, forwarders, and multi-region architectures.
- Design, develop, and sustain custom Splunk dashboards and analytics supporting:
- Security events, audit data, and user activity monitoring (UAM)
- STE/STN compliance, vulnerability and compliance scans
- Network/system observable events by SSP
- Containerized application events by namespace
- Mission metrics, outage tracking, and system/network utilization
- Ensure Splunk dashboards and logging infrastructure maintain =93% operational availability monthly.
- Develop and maintain dashboards for authentication events, privileged access, account management, role escalation, and container security events.
- Integrate data from NetFlow/sFlow, Syslog, Cribl, Nagios, HP NNMi, HPNA, vulnerability scanners, and compliance tools.
- Perform Splunk scaling, performance tuning, data onboarding, and index management.
- Maintain log retention policies ensuring:
- 30 days online searchable logs
- 5 years, 11 months offline retention with restore capability
- Provide Tier-4 support, including vendor escalation and coordination with Splunk engineering.
- Advise architects and security accreditors on Splunk security configurations and audit capabilities.
- Develop automation, parsing, and enrichment logic to reduce false positives and enhance alert fidelity.
Requirements
- Splunk Enterprise architecture and administration
- Security logging, SIEM design, and compliance reporting
- Linux systems administration
- Data onboarding (Syslog, NetFlow, API ingestion)
- Scripting (Python, Bash, SPL)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DS
Dhannush Subramani
about 4 years ago
EM
Eli McGarvie
Highest Paying Tech Companies for Developers
over 3 years ago
EM
Eli McGarvie
DevOps Engineer Salary [2023]
over 3 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
CH
Chris Heilmann
Dev Digest 131 - AI'm not sure about OSS
almost 2 years ago
DC
Daniel Cranney
Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters
over 1 year ago