Platform Engineer

Lintasarta

Jakarta Pusat

On-site

IDR 884,799,000 - 1,946,558,000

Full time

46 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lintasarta is seeking a Senior Platform Engineer to own Splunk ES deployments, data lake pipelines, and SOAR orchestration. You will direct multi-tier Splunk architectures, CIM mapping, and RBA integration, while partnering with IT/DevOps for agent rollout and health checks.

The role emphasizes automation, cloud logging, and high-availability strategies to maintain 24/7 operations across enterprise security platforms.

Qualifications

  • 5–7+ years in Infrastructure, DevOps, Cloud, or Enterprise Admin roles.
  • 3+ years focused on Splunk ES deployment and ES apps.
  • Experience with multi-tier Splunk environments and data pipelines.

Responsibilities

  • Oversee full lifecycle of SOC platforms (SIEM/SOAR/EDR/TIP).
  • Architect and manage high-volume data ingestion pipelines.
  • Tune query performance; ensure 24/7/365 reliability.
  • Develop API integrations and automated playbooks for IR teams.
  • Deploy and manage EDR/logging agents with IT/DevOps.

Skills

Splunk ES
DMA (Data Model Acceleration)
CIM Compliance
RBA Implementation
Data Streams / Cribl
KQL / SPL
Python / Bash
Cloud (AWS/Azure)
Linux / Windows Admin
DevOps / IaC

Tools

Cribl Stream
Kafka
Heavy Forwarders
Terraform
Ansible
Docker
Kubernetes

Job description

  • Platform Management: Oversee the full lifecycle—architecture, deployment, patching, clustering, and health monitoring—of core SOC platforms (SIEM, SOAR, EDR, TIP).
  • Data Pipeline Engineering: Architect and manage high-volume data ingestion pipelines, ensuring logs from cloud environments, networks, and endpoints are cleanly parsed, normalized, and indexed.
  • Storage & Retention Optimization: Optimize index storage strategies, hot/cold data tier configurations, and long-term compliance log archival to balance operational speed with hardware costs.
Automation & Integration (SOAR)
  • API Integration: Connect disparate security platforms, infrastructure systems, and identity providers by writing robust, secure custom API integrations.
  • Playbook Infrastructure: Engineer the backend infrastructure, actions, and custom connectors required for Tier-2 and Incident Response teams to execute automated response playbooks.
  • Agent Deployment: Partner with IT and DevOps teams to manage the automated enterprise-wide deployment, tuning, and health verification of EDR and logging agents.
Performance Tuning & Reliability
  • Query Performance Optimization: Audit, test, and tune complex analytical queries (e.g., Splunk SPL, Sentinel KQL) written by detection engineers to prevent system resource exhaustion.
  • High Availability: Implement and test robust backup, disaster recovery, and failover strategies for all critical SOC infrastructure components to guarantee 24/7/365 uptime.
Technical Skills & Tools
  • SIEM/Data Lake Engineering: Deep architectural knowledge of enterprise platforms, such as Splunk Enterprise (Clustering, Indexer/Search Head architecture), Microsoft Sentinel, Elastic Cloud (ELK), or Cribl Stream.
  • SOAR Infrastructure: Infrastructure-level experience managing orchestration engines like Palo Alto Cortex XSOAR, Splunk SOAR, or Swimlane.
  • DevOps & Infrastructure as Code (IaC): High proficiency deploying infrastructure and configurations using Terraform, Ansible, Docker, or Kubernetes clusters.
  • System Administration: Enterprise-level Linux (RHEL, Ubuntu) and Windows Server systems administration, including performance tuning, daemon management, and access controls.
  • Automation Languages: Advanced scripting capabilities in Python, Bash, or Go to build automated utilities, parse custom logs, and manipulate JSON/XML payloads over REST APIs.
  • Cloud Architecture: Deep experience managing native security logging mechanisms across AWS (CloudTrail, VPC Flow), Azure (Event Hubs), and GCP (Pub/Sub).
Experience & Qualifications
Required Experience
  • Total Systems Engineering Experience: Minimum of 5–7+ years of professional experience in Infrastructure Engineering, DevOps, Cloud Architectures, or Enterprise Systems Administration.
  • Splunk Platform Engineering Footprint: At least 3+ years of dedicated experience architecting, deploying, and maintaining large-scale Splunk environments, with explicit responsibility for managing Splunk Enterprise Security (ES) premium applications.
  • Architecture Scale: Documented history of engineering multi-tier Splunk environments (Clustered Indexers, Search Head Clusters, deployment servers) handling multi-terabyte per day data ingestion pipelines.
Splunk ES Specialized Experience
  • Data Model Acceleration: Proven experience configuring, tuning, and troubleshooting Data Model Accelerations (DMA) within Splunk ES to keep search head performance optimized without exhausting storage or CPU infrastructure.
  • CIM Compliance Engineering: Mastery of mapping unstructured log sources (firewall, cloud, identity, endpoint) to the Splunk Common Information Model (CIM) to ensure seamless alerting inside the ES incident review dashboard.
  • RBA Implementation: Direct hands-on experience structuring infrastructure to support Splunk Risk-Based Alerting (RBA) frameworks, including managing risk indexes and object attributions.
  • Data Stream Optimization: Proficiency utilizing Splunk Heavy Forwarders, Splunk Stream, or edge-routing technology (e.g., Cribl Stream, Kafka) to mask, filter, and drop duplicate event streams before they impact Splunk licensing costs.
Preferred Professional Certifications:
  • Splunk Core Certified Consultant
  • Splunk Enterprise Security Certified Admin (Highly Preferred)
  • Certified Information Systems Security Professional (CISSP)
  • AWS or Microsoft Azure Solutions Architect
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Platform Engineer — SOC Data Pipelines & Reliability
Senior Platform Engineer — SOC Data Pipelines & Reliability

Lintasarta • Jakarta Pusat

On-site
IDR 884,799,000 - 1,946,558,000
Threat Hunter
Threat Hunter

Lintasarta • Jakarta Pusat

On-site
IDR 40,000,000 - 70,000,000
Site Reliability Engineer
Site Reliability Engineer

CIMB Niaga • Tangerang Selatan

On-site
IDR 350,000,000 - 550,000,000
Senior DevOps Engineer
Senior DevOps Engineer

Vidio • Jakarta Pusat

On-site
IDR 300,000,000 - 500,000,000
Cloud Infrastructure Engineer
Cloud Infrastructure Engineer

PT Media Indonusa (Jakarta) • Jakarta Utara

On-site
IDR 420,000,000 - 540,000,000
Security Platform Engineer
Security Platform Engineer

Ajaib • Jakarta Pusat

On-site
IDR 200,000,000 - 320,000,000
Splunk Engineer
Splunk Engineer

Esha Parama Technology • Jakarta Pusat

Hybrid
IDR 279,000,000 - 502,200,000
Security Platform Engineer
Security Platform Engineer

Ajaib Group • Jakarta Pusat

On-site
Cloud Engineer - SOC Monitoring
Cloud Engineer - SOC Monitoring

PT Sentra Paramitra • Jakarta Pusat

On-site
IDR 200,880,000 - 357,120,000
Data Engineer
Data Engineer

Super Bank Indonesia • Jakarta Pusat

On-site
IDR 250,000,000 - 420,000,000