Splunk Admin

Devopster IT Consultants
Reading, UK
23 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
£78,000.0 - £91,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Application Services User Authentication Microsoft Azure Backup Devices Bash Shell Cloud Computing Cyber Security Linux DevOps Disaster Recovery
+23 more
Networking Hardware Python (Programming Language) Lightweight Directory Access Protocols (LDAP) Linux System Administration Parsing Performance Tuning Windows PowerShell Role-Based Access Control Ansible Runbook Security Information and Event Management Syslog Cloud Platform System Data Ingestion Mitre Att&ck Indexer Kubernetes Terraform Splunk Network Server Devsecops Docker Servicenow

Job description

We are looking for an experienced Splunk Engineer / Licence Manager to manage, optimise, and support our enterprise Splunk environment. The successful candidate will be responsible for Splunk platform administration, licence management, onboarding new data sources, performance optimisation, and ensuring high platform availability across multiple environments., * Administer and maintain Splunk Enterprise and/or Splunk Cloud environments.

  • Manage Splunk licensing, monitor daily licence consumption, and optimise licence usage across business units.
  • Investigate and resolve licence violations, indexing issues, and ingestion bottlenecks.
  • Design, implement, and maintain Splunk indexers, search heads, deployment servers, and forwarders.
  • Onboard new log sources from servers, applications, cloud platforms, security tools, and network devices.
  • Develop and optimise Splunk searches, dashboards, reports, alerts, and knowledge objects.
  • Monitor platform health, storage, indexing performance, and search efficiency.
  • Perform Splunk upgrades, patching, backup, disaster recovery, and capacity planning.
  • Integrate Splunk with cloud platforms (AWS/Azure), SIEM, security tools, and third-party applications.
  • Support troubleshooting of data ingestion, parsing, field extractions, and CIM compliance.
  • Work closely with Security Operations, DevOps, Infrastructure, and Application teams.
  • Produce operational documentation, runbooks, and technical procedures.
  • Ensure compliance with security standards and organisational governance.

Requirements

Candidates with Splunk Admin Certification and experience supporting enterprise-scale deployments are highly preferred., * 3+ years’ hands-on experience administering Splunk Enterprise.

  • Strong understanding of Splunk architecture:
  • Indexers
  • Search Heads
  • Deployment Servers
  • Heavy Forwarders
  • Universal Forwarders
  • Cluster Management
  • Experience managing Splunk licensing and licence pools.
  • Strong SPL (Search Processing Language) skills.
  • Experience onboarding Windows, Linux, Syslog, Cloud, and application logs.
  • Knowledge of RBAC, authentication, LDAP/AD integration, and security best practices.
  • Experience with Linux administration.
  • Experience troubleshooting distributed Splunk environments.
  • Understanding of monitoring, observability, and log management principles.
  • Excellent analytical and problem-solving skills.

Desirable Skills

  • Splunk Enterprise Certified Admin (Highly Preferred)
  • Splunk Enterprise Security (ES) experience.
  • Splunk ITSI experience.
  • AWS and/or Azure experience.
  • Kubernetes and Docker knowledge.
  • Python, Bash, or PowerShell scripting.
  • Experience with CI/CD pipelines.
  • Infrastructure as Code (Terraform/Ansible).
  • Experience with ServiceNow integration.
  • Knowledge of MITRE ATT&CK, SIEM, and SOC operations.

Certifications (Preferred)

  • Splunk Enterprise Certified Admin
  • Splunk Core Certified Power User
  • Splunk Enterprise Certified Architect
  • AWS Certified Solutions Architect
  • Microsoft Azure Administrator
  • ITIL Foundation

Personal Attributes

  • Strong communication and stakeholder management skills.
  • Ability to work independently and within cross-functional teams.
  • Detail-oriented with a proactive approach to problem solving.
  • Strong documentation and organisational skills.
  • Comfortable working in regulated and security-focused environments.

Nice to Have

  • Experience supporting large enterprise Splunk environments (500GB+/day ingestion).
  • Knowledge of Security Operations Centres (SOC).
  • Experience with DevSecOps and observability platforms.
  • Experience in UK Government, Defence, Finance, or other regulated industries.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

Videos

See all

Related articles

See all