Splunk Engineer/Administrator,
Job Description
Job Title: Splunk Engineer/Administrator
Location: San Antonio, TX / Irvine, CA
Duration: Long Term (12+ months)
Visa: USC or GC
Qualifications:
· 10+ years of overall IT experience.
· 3+ years’ experience in managing, designing, configuring Splunk environment (both on-prem and cloud)
· 3+ years’ experience in a Linux environment, including administration, scripting, or supporting applications.
· Experience with Splunk Enterprise Security Premium Application and Splunk Enterprise.
· Experience in requirement gathering and documentation.
· Experience in developing and supporting Splunk applications.
· Experience in automation with programming languages like Python, Java, .Net, and Ansible is a plus.
· Experience in technologies like GIT, JIRA, and automation testing.
· Familiarity with Phantom, Cloud computing, Web Interfaces, databases, and Big Data technologies (like Hadoop, Kafka etc.)
· Understanding of Continuous Delivery and Continuous Integration.
·Splunk Admin Certification is mandatory.
· Excellent communication and interpersonal skills.
· Splunk core admin experience is mandatory.
Responsibilities:
· Support, administer, maintain, and expand Splunk infrastructure to meet future architecture design and deployment requirements.
· Develop distributed Splunk applications, including requirement gathering and coordinating Splunk setup.
· Recommended Splunk implementation best practices and fixes.
· Design, implement, and optimize Splunk applications (to include Enterprise Security), queries, knowledge objects, and data models.
· Perform basic and advanced scripting tasks with Splunk to automate repeatable processes using Python.
· Deploy best practices for developing Splunk apps and create conceptual architecture for a continuous improvement initiative.
· Provide impact assessment for migration efforts.
· Support performance testing and user acceptance testing.
· Design and implement custom searches and reports.
· Build proof of concepts for Splunk enhancements.
· Tuning the information model and defining reusable templates.
· Define reusable view templates and retention & archival policies.
· Provide impact assessment for migration efforts and coordinate migration activities.
Nice to Have:
· Experience in security information and event management (SIEM).
· Experience with RTIR.
· Certifications in Splunk, CISSP, or similar.
Similar Jobs
Splunk Engineer/Administrator
California
Senior Splunk Infrastructure Engineer
North Carolina
Splunk Lead
California
Splunk Engineer/Administrator
California
Splunk Consultant
Remote