Job Summary
We are looking for a skilled and experienced Splunk Engineer to design, develop, and optimize our Splunk Cloud Platform with related data pipelines and Splunk Observability Cloud. In this role, you will be responsible for building scalable architectures, developing advanced SPL logic, integrating complex data sources, and partnering with IT, Security, DevOps, and Cloud teams to deliver deep operational insights and automation. This position is ideal for someone who enjoys solving complex data challenges, automating workflows, designing distributed systems, and enabling teams with high‑quality analytics.
Key Responsibilities
Architecture & Platform Engineering • Support design and implement scalable Splunk architectures (Distributed, clustered, hybrid, or cloud) - optional • Develop and maintain Search Head Clusters, Indexer Clusters, and multi‑site architectures • Plan capacity, storage tiering, data retention, and scaling strategies • Drive platform modernization (cloud migration, automation, OTel, containerization) • Data Engineering & Integration • Develop and manage ingestion pipelines for large-scale, complex data sources. • Create and optimize parsing, indexing, routing, and enrichment logic (props/transforms) • Integrate Splunk with external platforms via REST APIs, HEC, Kafka, syslog, or custom collectors • Automate data onboarding standards and implement governance and data normalization frameworks • Use Case & Content Development • Build advanced SPL queries, correlation logic, dashboards, and reports • Develop reusable knowledge objects (lookups, event types, macros, data models). • Partner with Security and Operations to implement SIEM, Observability, or IT analytics use cases • Support creation of KPIs, SLIs, and SLOs for service health and incident reduction • Automation & CI/CD • Create automated workflows for deployments, configuration, and testing (Git, Ansible, CI/CD) • Build self‑service onboarding mechanisms for logs and metrics • Develop scripts (Python, Bash, PowerShell) to eliminate operational manual work • Performance & Optimization • Tune search performance and platform performance (search acceleration, summaries, KV‑stores) • Perform root‑cause analysis on ingestion or search performance issues • Improve cost efficiency by optimizing data volume, index strategy, and retention policies • Cross‑Team Collaboration • Act as a technical expert for Splunk across multiple teams (IT Ops, Cloud, Network, Security) 3+ years of experience with Splunk Enterprise or Splunk Cloud in engineering or architecture roles. • Strong expertise in o SPL (complex searches, tuning, correlation logic) o Indexing, parsing, props/transforms o Cluster setup, distributed architectures o Forwarders (UF/HF), HEC, and ingestion pipelines • Hands-on scripting experience (Python, Bash, PowerShell) • Solid understanding of Linux systems, networking, and logging frameworks • Experience with CI/CD tools • Experience working with REST APIs or custom data integrations
Skill Requirements
Experience with o Splunk Enterprise Security (ES) o Cloud & container environments (AWS, Azure, Kubernetes) o Observability platforms (OpenTelemetry, Splunk Observability, Prometheus) o Infrastructure-as-Code (Terraform, Ansible) • Splunk certifications (Architect, Power User, Admin, ES/ITSI) preferred.
Other Requirements
Strong analytical and problem‑solving mindset. • Ability to translate business requirements into technical Splunk solutions. • Clear communication skills with both technical and non‑technical stakeholders. • Ability to work independently and drive solutions from concept to implementation. • Passion for automation, quality, and continuous improvement.