You will design, deploy, and manage scalable Splunk SIEM architectures and backend operations.
This role is hybrid.
Responsibilities
Design and implement scalable SIEM architectures, including backend operations for Universal Forwarders, Heavy Forwarders, Search Heads, and Indexer Clusters.
Manage log collection, parsing, normalization, and retention strategies while optimizing license usage through effective filtering and re-routing.
Integrate Splunk logging infrastructure with third-party observability tools and produce technical documentation including HLD, LLD, implementation guides, and operation manuals.
Apply data parsimony concepts and security standards to ensure efficient and compliant log management.
Required Skills
10+ years of experience with Splunk backend architecture and operations.
Expertise in Splunk SIEM, log management, and license optimization.
Strong Linux Administration skills.
Proficiency in scripting with Python, PowerShell, or Bash for task automation.
Deep understanding of Network Architecture and its impact on logging components.
Working knowledge of Syslog and data parsing techniques.
Degree in any graduate field.
Preferred Skills
Experience with open source or third-party observability tools like ELK or DataDog.