Splunk Administrator

Belcan
Des Moines, IA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$95,000.0 - $105,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Microsoft Online Services Cloud Computing Data Normalization Data Retention Database Queries Linux DevOps Document Management Systems Document-Oriented Databases Microsoft Exchange Server
+36 more
Identity and Access Management Information Technology Operations Networking Hardware Intrusion Detection and Prevention Python (Programming Language) Lightweight Directory Access Protocols (LDAP) Linux System Administration Microsoft Security Essentials Windows Servers Parsing Performance Tuning Windows PowerShell Role-Based Access Control Azure Active Directory Ansible Security Assertion Markup Language (SAML) Microsoft SharePoint Security Information and Event Management Syslog User Provisioning Software Data Logging Scripting Load Balancing Cloud Platform System Data Ingestion System Availability Database Optimization Microsoft InTune Microsoft Onedrive Deployment Automation Cloud Connectors Puppet Terraform Splunk Network Server Servicenow

Job description

The Splunk & Microsoft 365 Administrator will be responsible for managing, monitoring, and optimizing the enterprise Splunk platform and Microsoft 365 environment. The role includes administration of Microsoft Exchange Online, Teams, SharePoint Online, OneDrive, Azure AD/Entra ID, and Microsoft security solutions, while ensuring the reliability, security, and performance of Splunk infrastructure used for log management, monitoring, and security analytics.

The ideal candidate should possess strong troubleshooting skills, experience supporting enterprise collaboration platforms, and expertise in SIEM, monitoring, and cloud administration.

Job Duties:

  • Platform Management
  • Install, configure, and maintain Splunk Enterprise and Splunk Universal Forwarders.
  • Manage Splunk indexers, search heads, deployment servers, cluster masters, and heavy forwarders.
  • Oversee Splunk architecture for performance, scalability, and high availability.
  • Apply patches, upgrades, and version migrations while ensuring platform stability.
  • Data Onboarding & Parsing
  • Onboard new data sources (syslog, APIs, agents, cloud connectors, Windows/Linux logs).
  • Create and maintain inputs.conf, props.conf, and transforms.conf.
  • Develop field extractions, sourcetypes, timestamps, and line-breaking rules.
  • Ensure proper data normalization and schema alignment (CIM compliance where needed).
  • Search, Dashboards, and Visualization
  • Build and optimize SPL queries for dashboards, alerts, reports, and scheduled searches.
  • Develop enterprise-grade dashboards and visualizations for IT operations, security, and business teams.
  • Tune saved searches for performance and resource efficiency.
  • Monitoring, Alerting & Incident Support
  • Create operational and security alerts aligned with business/service requirements.
  • Monitor ingestion volumes, license usage, disk utilization, and system health.
  • Troubleshoot ingestion delays, search performance issues, missing data, and forwarder connectivity.
  • Support incident management teams by providing log insights and analysis.
  • Security & Compliance
  • Manage authentication/authorization (LDAP/AD, SAML, RBAC).
  • Implement access controls, user roles, and knowledge object permissions.
  • Ensure compliance with audit requirements and log retention policies.
  • Maintain data integrity and support security teams in SIEM workflows (if correlated with ES).
  • Performance Tuning & Optimization
  • Optimize index configurations, search head performance, and data retention strategies.
  • Perform load balancing and clustering health checks.
  • Identify inefficient SPL queries and improve search performance.
  • Automation & DevOps
  • Automate deployment of apps, configurations, and forwarders using deployment server or CI/CD pipelines.
  • Create scripted inputs, modular inputs, and REST-based integrations.
  • Utilize tools such as Ansible, Puppet, or Terraform for Splunk environment automation.
  • Documentation & Governance
  • Document data onboarding, field extractions, dashboards, and operational procedures.
  • Maintain runbooks, SOPs, and architectural diagrams.
  • Work with governance teams to validate logging requirements and retention schedules.
  • Collaboration & Customer Support
  • Partner with application teams, network teams, and security analysts to deliver logging solutions.
  • Consult internal stakeholders on best practices for dashboards, alerts, and log ingestion.
  • Provide training for Splunk usage, SPL query writing, and dashboard development., Splunk Administration
  • Install, configure, and maintain Splunk Enterprise and Splunk Cloud environments.
  • Manage Splunk Indexers, Search Heads, Forwarders, Deployment Servers, and Clusters.
  • Develop and maintain dashboards, reports, alerts, and monitoring solutions.
  • Configure log ingestion from servers, applications, network devices, and cloud platforms.
  • Optimize Splunk performance, retention policies, and indexing strategies.
  • Perform troubleshooting and root cause analysis of Splunk platform issues.
  • Support security monitoring, threat detection, and compliance reporting requirements.
  • Design and implement Splunk use cases for operational and security monitoring.
  • Work with infrastructure and security teams to onboard new data sources.

Microsoft 365 Administration

  • Administer Microsoft 365 tenant, including Exchange Online, Teams, SharePoint Online, OneDrive, and Microsoft Purview.
  • Manage user provisioning, licensing, groups, and role assignments through Microsoft Entra ID (Azure AD).
  • Configure and support Microsoft Teams policies, calling, meetings, and collaboration services.
  • Administer Exchange Online mailboxes, mail flow, distribution groups, and hybrid configurations.
  • Manage SharePoint Online sites, permissions, and document management solutions.
  • Monitor service health and proactively address performance or availability issues.
  • Support Microsoft Defender and security compliance initiatives.
  • Implement data retention, DLP, eDiscovery, and governance policies.
  • Coordinate tenant migrations, upgrades, and adoption initiatives.

Security & Compliance

  • Ensure adherence to security standards and compliance requirements.
  • Support identity and access management using Entra ID and Conditional Access.
  • Configure MFA, SSO, and security policies for Microsoft 365 services.
  • Monitor and investigate security alerts from Splunk and Microsoft Security tools.
  • Participate in security audits and remediation activities.

Operations & Support

  • Support Incident, Problem, Change, and Request Management processes.
  • Troubleshoot complex infrastructure and application issues.
  • Create and maintain operational documentation and knowledge articles.
  • Participate in on-call and after-hours support activities as required.
  • Collaborate with cross-functional teams to ensure service availability and customer satisfaction., * Windows Server Administration
  • Linux Administration
  • PowerShell
  • Basic Python or scripting knowledge
  • ITSM & Monitoring
  • ServiceNow
  • ITIL Processes
  • Monitoring & Alerting Platforms

Requirements

Preferred Qualifications & Skills:

  • Splunk
  • Splunk Enterprise
  • Splunk Cloud
  • Splunk Enterprise Security (ES)
  • Splunk ITSI (preferred)
  • Universal Forwarders
  • Search Processing Language (SPL)
  • Dashboard Development
  • Log Management & Monitoring
  • Data Onboarding & Parsing
  • Alerting & Reporting
  • Microsoft 365
  • Exchange Online
  • Microsoft Teams
  • SharePoint Online
  • OneDrive for Business
  • Microsoft Entra ID (Azure AD)
  • Microsoft Defender
  • Microsoft Purview
  • Intune (preferred)
  • Power Platform (preferred)
  • Identity & Security
  • SSO
  • MFA

Benefits & conditions

We provide a competitive pay and benefits package. This position is offering a salary range of $95,000-$105,000 Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all