We are seeking an experienced Splunk Subject Matter Expert to lead the design, implementation, and optimization of Splunk solutions across security operations and observability domains. This role serves as the technical authority on Splunk architecture, driving enterprise-wide deployments for security monitoring, threat detection, and comprehensive observability across hybrid and multi-cloud environments.
Security Operations & Threat Detection :
- Design and implement Splunk Enterprise Security (ES) deployments including correlation searches, notable event management, risk-based alerting, and threat intelligence framework integration.
- Develop and optimize security use cases covering MITRE ATT&CK tactics, insider threat detection, anomaly detection, and APT hunting.
- Build Splunk SOAR playbooks for security orchestration, automated response workflows, and cross-platform integrations.
- Implement User and Entity Behavior Analytics (UBA) to detect insider threats, compromised credentials, and behavioral anomalies.
Observability & Performance Monitoring :
- Architect and deploy Splunk Observability Cloud solutions including Infrastructure Monitoring, APM, RUM, and Log Observer.
- Implement OpenTelemetry instrumentation for distributed tracing, metrics, and correlation across microservices.
- Build synthetic monitoring and alerting strategies for proactive detection of performance and availability issues.
Integration & Data Pipeline Management :
- Integrate diverse data sources across AWS, Azure, GCP, EDR tools, firewalls, IDS/IPS, network devices, applications, and databases.
- Design API integrations, webhook configurations, and custom scripted inputs for specialized collection needs.
- Implement Splunk HEC with load balancing, encryption, and token governance.
- Develop custom TAs and applications to extend Splunk capabilities.
Client Engagement & Solution Delivery :
- Lead technical discovery workshops and design target-state Splunk architectures.
- Develop architecture diagrams, implementation guides, runbooks, and knowledge transfer materials.
- Provide mentorship on Splunk administration, SPL optimization, dashboards, and alerts.
- Manage POCs and pilots demonstrating Splunks value across security and observability.
- Serve as escalation point for complex technical and architectural issues.
Required Qualifications Technical Expertise :
- 7 to 10 years experience with Splunk Enterprise, including 3+ in architect or senior admin roles.
- Deep expertise in Splunk Enterprise Security and SOC solution design.
- Strong experience with Splunk Observability Cloud including APM, Infra Monitoring, and RUM.
- Advanced SPL skills including optimized queries, regex, field extraction, and CIM mapping.
- Experience with Splunk SOAR automation and orchestration.
Security & Compliance Knowledge :
- Strong understanding of MITRE ATT&CK, NIST CSF, and Kill Chain methodologies.
- Experience with PCI-DSS, HIPAA, GDPR, SOC 2, and ISO 27001 compliance monitoring.
- Knowledge of threat intelligence platforms, IOC management, and threat hunting.
Infrastructure & Cloud Platforms :
- Experience with AWS, Azure, GCP native logging, security monitoring, and cost optimization.
- Understanding of Docker, Kubernetes, microservices, and cloud-native observability.