Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
EI

Splunk Engineer

Expert In Recruitment Solutions
๐Ÿ‡บ๐Ÿ‡ธ United States
On-site
2 months ago
  • Splunk
  • Incident Response
  • SIEM
  • Change Management
  • Incident Management
  • Linux
  • AWS
  • Azure
  • GCP
  • RHEL
  • Windows Server
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Title: Splunk Engineer Location: Hybrid/Onsite 3 days a week - Charlotte, NC or Plano, TX


The engineer will act as a trusted platform owner, ensuring Splunk availability, scalability, and reliability while partnering closely with Information Security, SOC, architecture, engineering, and operations teams. This role will own end-to-end production support for a highly distributed Splunk Enterprise and Splunk Cloud environment.

Responsibilities:
  • Ensure high availability, performance, and resiliency of the Splunk platform supporting security and operational use cases
  • Lead incident response, troubleshooting, root cause analysis (RCA), and service restoration for Splunk and Cribl platforms
  • Proactively identify risks, capacity constraints, and performance bottlenecks; implement preventive and tuning measures
  • Serve as a key technical enabler for Information Security and SOC teams, ensuring timely, accurate, and reliable ingestion of security logs
  • Onboard and normalize new data sources, supporting CIM compliance, field normalization, and SIEM best practices
  • Tune ingestion pipelines using props.conf and transforms.conf, index-time and search-time optimizations
  • Build and support dashboards, searches, and alerts that enable threat detection, investigations, and reporting
  • Administer and support the Cribl environment for data routing, filtering, enrichment, and cost optimization
  • Develop and maintain runbooks, SOPs, installation guides, and operational documentation
  • Adhere to change management, incident management, and SLA commitments using ITSM tools
Requirements:
  • 5+ years of hands-on experience administering large-scale Splunk Enterprise or Splunk Cloud environments
  • Strong expertise in Indexer clustering, search head clustering, Universal and heavy forwarder architectures, SmartStore/S3-compatible object storage, and SPL
  • Deep experience with security log ingestion and SIEM use cases
  • Proven ability to lead production incidents, perform RCA, and drive preventive solutions
  • Strong Linux administration skills and experience managing Splunk configuration and apps
  • Experience working in 24x7 production environments with high availability expectations
  • Excellent written and verbal communication skills, with the ability to engage senior technical and business stakeholders
Desired skills:
  • A production owner's mindset and deep technical credibility in Splunk and data pipelines
  • Ability to operate calmly and decisively during high-severity security and platform incidents
  • Splunk certifications such as Enterprise Admin or Enterprise Architect
  • Experience with Splunk Enterprise Security (ES) and SOAR (Phantom or equivalent)
  • Exposure to cloud logging and security architectures (AWS, Azure, GCP)
  • Knowledge of Red Hat Enterprise Linux and Windows Server administration
  • Experience with monitoring, APM, and event management tools
  • Strong understanding of security, network, system, and database operations
  • Ability to balance multiple priorities in a fast-paced, enterprise production environment

Splunk Engineer ยท Expert In Recruitment Solutions

Auto apply with Likeremote