Splunk Engineer

fuse
Meade, KS, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Bash Shell Computer Networks Python (Programming Language) Linux System Administration Nagios NetFlow Performance Tuning Security Information and Event Management Syslog Data Logging Scripting
+4 more
Data Ingestion Containerization Splunk Vulnerability Analysis

Job description

The Splunk Engineer is responsible for the design, implementation, optimization, and sustainment of enterprise logging, monitoring, and security analytics solutions. This role ensures Splunk environments meet availability, performance, compliance, and audit requirements ., * Architect, deploy, and maintain enterprise Splunk environments, including indexers, search heads, forwarders, and multi-region architectures.

  • Design, develop, and sustain custom Splunk dashboards and analytics supporting:
  • Security events, audit data, and user activity monitoring (UAM)
  • STE/STN compliance, vulnerability and compliance scans
  • Network/system observable events by SSP
  • Containerized application events by namespace
  • Mission metrics, outage tracking, and system/network utilization
  • Ensure Splunk dashboards and logging infrastructure maintain =93% operational availability monthly.
  • Develop and maintain dashboards for authentication events, privileged access, account management, role escalation, and container security events.
  • Integrate data from NetFlow/sFlow, Syslog, Cribl, Nagios, HP NNMi, HPNA, vulnerability scanners, and compliance tools.
  • Perform Splunk scaling, performance tuning, data onboarding, and index management.
  • Maintain log retention policies ensuring:
  • 30 days online searchable logs
  • 5 years, 11 months offline retention with restore capability
  • Provide Tier-4 support, including vendor escalation and coordination with Splunk engineering.
  • Advise architects and security accreditors on Splunk security configurations and audit capabilities.
  • Develop automation, parsing, and enrichment logic to reduce false positives and enhance alert fidelity.

Requirements

  • Splunk Enterprise architecture and administration
  • Security logging, SIEM design, and compliance reporting
  • Linux systems administration
  • Data onboarding (Syslog, NetFlow, API ingestion)
  • Scripting (Python, Bash, SPL)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

3:37 min

Why differing legacy workflows complicate monitoring tool migrations

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:30 min

Managing transforms and objectives via developer tools APIs

Diana Todea · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all