Splunk Admin

Devopster IT Consultants
Reading, United Kingdom
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
£ 91K

Job location

Remote
Reading, United Kingdom

Tech stack

Microsoft Windows
Amazon Web Services (AWS)
Application Services
User Authentication
Azure
Backup Devices
Bash
Cloud Computing
Computer Security
Linux
DevOps
Disaster Recovery
Networking Hardware
Python
Lightweight Directory Access Protocols (LDAP)
Linux System Administration
Parsing
Performance Tuning
Powershell
Role-Based Access Control
Ansible
Runbook
Security Information and Event Management
Syslog
Cloud Platform System
Data Ingestion
Mitre Att&ck
Indexer
Kubernetes
Terraform
Splunk
Network Server
Devsecops
Docker
ServiceNow

Job description

We are looking for an experienced Splunk Engineer / Licence Manager to manage, optimise, and support our enterprise Splunk environment. The successful candidate will be responsible for Splunk platform administration, licence management, onboarding new data sources, performance optimisation, and ensuring high platform availability across multiple environments., * Administer and maintain Splunk Enterprise and/or Splunk Cloud environments.

  • Manage Splunk licensing, monitor daily licence consumption, and optimise licence usage across business units.
  • Investigate and resolve licence violations, indexing issues, and ingestion bottlenecks.
  • Design, implement, and maintain Splunk indexers, search heads, deployment servers, and forwarders.
  • Onboard new log sources from servers, applications, cloud platforms, security tools, and network devices.
  • Develop and optimise Splunk searches, dashboards, reports, alerts, and knowledge objects.
  • Monitor platform health, storage, indexing performance, and search efficiency.
  • Perform Splunk upgrades, patching, backup, disaster recovery, and capacity planning.
  • Integrate Splunk with cloud platforms (AWS/Azure), SIEM, security tools, and third-party applications.
  • Support troubleshooting of data ingestion, parsing, field extractions, and CIM compliance.
  • Work closely with Security Operations, DevOps, Infrastructure, and Application teams.
  • Produce operational documentation, runbooks, and technical procedures.
  • Ensure compliance with security standards and organisational governance.

Requirements

Candidates with Splunk Admin Certification and experience supporting enterprise-scale deployments are highly preferred., * 3+ years' hands-on experience administering Splunk Enterprise.

  • Strong understanding of Splunk architecture:
  • Indexers
  • Search Heads
  • Deployment Servers
  • Heavy Forwarders
  • Universal Forwarders
  • Cluster Management
  • Experience managing Splunk licensing and licence pools.
  • Strong SPL (Search Processing Language) skills.
  • Experience onboarding Windows, Linux, Syslog, Cloud, and application logs.
  • Knowledge of RBAC, authentication, LDAP/AD integration, and security best practices.
  • Experience with Linux administration.
  • Experience troubleshooting distributed Splunk environments.
  • Understanding of monitoring, observability, and log management principles.
  • Excellent analytical and problem-solving skills.

Desirable Skills

  • Splunk Enterprise Certified Admin (Highly Preferred)
  • Splunk Enterprise Security (ES) experience.
  • Splunk ITSI experience.
  • AWS and/or Azure experience.
  • Kubernetes and Docker knowledge.
  • Python, Bash, or PowerShell scripting.
  • Experience with CI/CD pipelines.
  • Infrastructure as Code (Terraform/Ansible).
  • Experience with ServiceNow integration.
  • Knowledge of MITRE ATT&CK, SIEM, and SOC operations.

Certifications (Preferred)

  • Splunk Enterprise Certified Admin
  • Splunk Core Certified Power User
  • Splunk Enterprise Certified Architect
  • AWS Certified Solutions Architect
  • Microsoft Azure Administrator
  • ITIL Foundation

Personal Attributes

  • Strong communication and stakeholder management skills.
  • Ability to work independently and within cross-functional teams.
  • Detail-oriented with a proactive approach to problem solving.
  • Strong documentation and organisational skills.
  • Comfortable working in regulated and security-focused environments.

Nice to Have

  • Experience supporting large enterprise Splunk environments (500GB+/day ingestion).
  • Knowledge of Security Operations Centres (SOC).
  • Experience with DevSecOps and observability platforms.
  • Experience in UK Government, Defence, Finance, or other regulated industries.

Apply for this position