About the job
Job Summary:
As a Senior Splunk Engineer, you will play a pivotal role in the design, execution, management, and enhancement of Splunk Enterprise or Splunk Cloud in a large-scale corporate or managed services framework. You will oversee log onboarding, develop correlation rules, create dashboards, and tune performance to ensure the Splunk platform provides precise, actionable insights for security operations and compliance monitoring.
Key Responsibilities:
- Architect and deploy comprehensive Splunk solutions encompassing data ingestion, parsing, indexing, and search optimization.
- Design and sustain custom correlation rules, alerts, dashboards, and visualizations to bolster security monitoring and incident response.
- Integrate new log sources from infrastructure, security, applications, and cloud systems using best practices (e.g., UF, HF, syslog, APIs).
- Conduct routine health assessments, performance tuning of indexers and search heads, monitor license usage, and secure configuration backups.
- Support threat detection efforts by converting security use cases into actionable Splunk queries and alerts.
- Assist in resolving ingestion failures, parsing issues, and inefficient search queries.
- Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, integrity, and quality.
- Oversee Splunk Enterprise Security (ES) configurations, ensuring CIM compliance, managing notables, and implementing risk-based alerting (RBA).
- Establish and manage data retention policies and storage optimization aligned with compliance mandates.
- Automate processes using scripting languages (Python, Bash, PowerShell) and configuration management tools as necessary.
- Provide technical mentorship and guidance to junior Splunk engineers and analysts.

