Splunk Engineer/Architect

Zachary Piper
Morrisville, NC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$140,000.0 - $180,000.0
Working hours
Regular working hours

Tech stack

Cluster Analysis Parsing Performance Tuning Security Information and Event Management Data Ingestion Mitre Att&ck Indexer Backend SC Clearance Splunk

Job description

Piper Companies is seeking a Splunk Engineer / Architect to support a leading organization in the cybersecurity and enterprise technology industry. The Splunk Engineer / Architect will play a critical role in designing, implementing, and optimizing enterprise-scale Splunk environments within a SOC, with a strong focus on backend engineering and architectural design rather than dashboarding or end-user analytics. The Splunk Engineer/Architect is a long term contract opportunity, requires an active Secret Clearance and requires you to work onsite 5 days per week in RTP, NC.

  • Design and deploy scalable, highly available Splunk architectures across on-prem, cloud, and hybrid environments.
  • Lead Splunk engineering efforts including installation, configuration, upgrades, and ongoing platform maintenance (indexers, search heads, forwarders, clustering).
  • Develop and execute data ingestion strategies, including onboarding, normalization, parsing, and performance optimization.
  • Establish governance, platform standards, and best practices to ensure long-term scalability and reliability.
  • Support SOC operations by building and tuning SIEM use cases, correlation searches, and alerts aligned with MITRE ATT&CK.
  • Collaborate with cybersecurity and infrastructure teams to enhance threat detection, monitoring, and incident response capabilities.

Requirements

  • 5+ years of hands-on Splunk Engineering/Architecture experience (backend focus, not dashboarding).
  • Strong expertise with Splunk Enterprise and Splunk Enterprise Security (ES) in large-scale environments.
  • Deep understanding of data ingestion, indexing, clustering (indexer/search head), and search optimization.
  • Experience supporting Splunk within a SOC and contributing to SIEM/security monitoring strategies.

Benefits & conditions

  • $140,000-$180,000
  • Full Comprehensive Benefits: Health, Vision, Dental, PTO, Paid Holiday and Sick Leave if Required by Law.

Keywords: Splunk, Splunk Engineer, Splunk Architect, SIEM, Splunk Enterprise, Splunk ES, Security Operations Center, SOC, data ingestion, indexer clustering, search head clustering, MITRE ATT&CK, threat detection, logging strategy, monitoring, cybersecurity, backend Splunk engineering, RTP jobs, active secret clearance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

2:36 min

Analyzing limitations with PostgreSQL bitmap heap scans

Dharin Shah Dharin Shah · WWC 2025

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · WWC 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:32 min

Generating functional runtime database columns using indexer properties

Halil İbrahim Kalkan Halil İbrahim Kalkan · WWC Europe 2026

Videos

See all

Related articles

See all