Splunk Administrator

Belcan LLC

Des Moines (IA)

On-site

USD 95,000 - 105,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Belcan LLC in Des Moines is seeking a Splunk & Microsoft 365 Administrator to manage Splunk and Microsoft 365 environments, including Exchange Online, Teams, SharePoint Online, OneDrive, and Entra ID, with focus on reliability, security, and performance.

The ideal candidate will have strong troubleshooting skills and expertise in SIEM, monitoring, and cloud administration, with 5–8 years of relevant experience.

Qualifications

  • 5–8 years in Splunk administration and security analytics.
  • Hands-on experience with Splunk Enterprise, Cloud, ES and ITSI.
  • Strong Microsoft 365 knowledge and Entra ID administration.
  • Experience with SIEM, data onboarding, parsing, and alerting.
  • Scripting with PowerShell or Python.

Responsibilities

  • Install, configure, and maintain Splunk Enterprise and Forwarders.
  • Manage indexers, search heads, deployment servers, and clusters.
  • Develop dashboards, alerts, and monitoring solutions.
  • Onboard data sources and ensure CIM alignment where needed.
  • Optimize performance, retention, and licensing for Splunk.
  • Administer Microsoft 365: Exchange Online, Teams, SharePoint, OneDrive, Purview.
  • Configure Entra ID, RBAC, MFA, SSO, and Conditional Access.
  • Support security monitoring, incident response, and audits.

Skills

ITSM & Monitoring
RBAC
Zero Trust Security
Scripting concepts

Education

Tools

Splunk
Splunk Enterprise
Splunk Cloud
Splunk Enterprise Security (ES)
Splunk ITSI (preferred)
Universal Forwarders
PowerShell
Python

Job description

Innovative, Secure, and Outcome-Based Solutions

Job Summary:

The Splunk & Microsoft 365 Administrator will be responsible for managing, monitoring, and optimizing the enterprise Splunk platform and Microsoft 365 environment. The role includes administration of Microsoft Exchange Online, Teams, SharePoint Online, OneDrive, Azure AD/Entra ID, and Microsoft security solutions, while ensuring the reliability, security, and performance of Splunk infrastructure used for log management, monitoring, and security analytics.

The ideal candidate should possess strong troubleshooting skills, experience supporting enterprise collaboration platforms, and expertise in SIEM, monitoring, and cloud administration.

Job Duties:

  • Platform Management
  • Install, configure, and maintain Splunk Enterprise and Splunk Universal Forwarders.
  • Manage Splunk indexers, search heads, deployment servers, cluster masters, and heavy forwarders.
  • Oversee Splunk architecture for performance, scalability, and high availability.
  • Apply patches, upgrades, and version migrations while ensuring platform stability.
  • Data Onboarding & Parsing
  • Create and maintain inputs.conf, props.conf, and transforms.conf.
  • Develop field extractions, sourcetypes, timestamps, and line-breaking rules.
  • Ensure proper data normalization and schema alignment (CIM compliance where needed).
  • Search, Dashboards, and Visualization
  • Build and optimize SPL queries for dashboards, alerts, reports, and scheduled searches.
  • Develop enterprise-grade dashboards and visualizations for IT operations, security, and business teams.
  • Tune saved searches for performance and resource efficiency.
  • Create operational and security alerts aligned with business/service requirements.
  • Monitor ingestion volumes, license usage, disk utilization, and system health.
  • Troubleshoot ingestion delays, search performance issues, missing data, and forwarder connectivity.
  • Support incident management teams by providing log insights and analysis.
  • Security & Compliance
  • Implement access controls, user roles, and knowledge object permissions.
  • Ensure compliance with audit requirements and log retention policies.
  • Maintain data integrity and support security teams in SIEM workflows (if correlated with ES).
  • Performance Tuning & Optimization
  • Optimize index configurations, search head performance, and data retention strategies.
  • Perform load balancing and clustering health checks.
  • Identify inefficient SPL queries and improve search performance.
  • Automation & DevOps
  • Automate deployment of apps, configurations, and forwarders using deployment server or CI/CD pipelines.
  • Create scripted inputs, modular inputs, and REST-based integrations.
  • Utilize tools such as Ansible, Puppet, or Terraform for Splunk environment automation.
  • Documentation & Governance
  • Document data onboarding, field extractions, dashboards, and operational procedures.
  • Maintain runbooks, SOPs, and architectural diagrams.
  • Work with governance teams to validate logging requirements and retention schedules.
  • Partner with application teams, network teams, and security analysts to deliver logging solutions.
  • Consult internal stakeholders on best practices for dashboards, alerts, and log ingestion.
  • Provide training for Splunk usage, SPL query writing, and dashboard development.

Key Responsibilities:

Splunk Administration

  • Install, configure, and maintain Splunk Enterprise and Splunk Cloud environments.
  • Manage Splunk Indexers, Search Heads, Forwarders, Deployment Servers, and Clusters.
  • Develop and maintain dashboards, reports, alerts, and monitoring solutions.
  • Configure log ingestion from servers, applications, network devices, and cloud platforms.
  • Optimize Splunk performance, retention policies, and indexing strategies.
  • Perform troubleshooting and root cause analysis of Splunk platform issues.
  • Support security monitoring, threat detection, and compliance reporting requirements.
  • Design and implement Splunk use cases for operational and security monitoring.
  • Work with infrastructure and security teams to onboard new data sources.

Microsoft 365 Administration

  • Administer Microsoft 365 tenant, including Exchange Online, Teams, SharePoint Online, OneDrive, and Microsoft Purview.
  • Manage user provisioning, licensing, groups, and role assignments through Microsoft Entra ID (Azure AD).
  • Configure and support Microsoft Teams policies, calling, meetings, and collaboration services.
  • Administer Exchange Online mailboxes, mail flow, distribution groups, and hybrid configurations.
  • Manage SharePoint Online sites, permissions, and document management solutions.
  • Monitor service health and proactively address performance or availability issues.
  • Support Microsoft Defender and security compliance initiatives.
  • Implement data retention, DLP, eDiscovery, and governance policies.
  • Coordinate tenant migrations, upgrades, and adoption initiatives.

Security & Compliance

  • Ensure adherence to security standards and compliance requirements.
  • Support identity and access management using Entra ID and Conditional Access.
  • Configure MFA, SSO, and security policies for Microsoft 365 services.
  • Monitor and investigate security alerts from Splunk and Microsoft Security tools.
  • Participate in security audits and remediation activities.

Operations & Support

  • Support Incident, Problem, Change, and Request Management processes.
  • Troubleshoot complex infrastructure and application issues.
  • Create and maintain operational documentation and knowledge articles.
  • Participate in on-call and after-hours support activities as required.
  • Collaborate with cross-functional teams to ensure service availability and customer satisfaction.

Required Qualifications:

  • Experience 5-8 Years

Preferred Qualifications & Skills:

  • Splunk
  • Splunk Enterprise
  • Splunk Cloud
  • Splunk Enterprise Security (ES)
  • Splunk ITSI (preferred)
  • Universal Forwarders
  • Search Processing Language (SPL)
  • Data Onboarding & Parsing
  • Alerting & Reporting
  • Microsoft 365
  • Exchange Online
  • Microsoft Teams
  • SharePoint Online
  • OneDrive for Business
  • Microsoft Purview
  • Power Platform (preferred)
  • Identity & Security
  • SSO
  • MFA
  • Conditional Access
  • RBAC
  • Zero Trust Security
  • Identity Governance
  • Operating Systems & Scripting
  • Windows Server Administration
  • PowerShell
  • Basic Python or scripting knowledge
  • ITSM & Monitoring
  • ServiceNow
  • ITIL Processes
  • Monitoring & Alerting Platforms

Compensation:

We provide a competitive pay and benefits package. This position is offering a salary range of $95,000-$105,000Belcan considers several factors when extending an offer, including but not limited to education, experience, geographic location, and discipline. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.

Belcan is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk & Microsoft 365 Security Admin
Splunk & Microsoft 365 Security Admin

Belcan LLC • Des Moines (IA)

On-site
USD 95,000 - 105,000
Senior Engineer
Senior Engineer

Hobbsnews • Charlotte (NC)

On-site
USD 122,000 - 200,000
Benefits eligible
Paid time off
Annual discretionary award
Splunk IT Administrator
Splunk IT Administrator

FLEETCOR • Peachtree Corners (GA)

On-site
USD 85,000 - 110,000
Medical, Dental & Vision benefits
401k plan
Virtual fitness classes
+4
TS/SCI Splunk Engineer — Mission-Critical Analytics
TS/SCI Splunk Engineer — Mission-Critical Analytics

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Splunk Engineer
Splunk Engineer

Peraton • Herndon (VA)

On-site
USD 112,000 - 179,000
Heavily subsidized benefits coverage
25 days PTO accrued annually
Attractive bonus plan
Senior Engineer
Senior Engineer

Bank of America • Pennington (NJ)

On-site
USD 122,000 - 200,000
Industry-leading benefits
Paid time off
Discretionary incentive eligible
Splunk Engineer
Splunk Engineer

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Senior Splunk Engineer
Senior Splunk Engineer

Xpect Solutions, Inc. • Washington

On-site
USD 120,000 - 150,000
Competitive Medical, Dental, and Vision plan
Retirement Savings Plan
Life Insurance
+3
Splunk Administrator/Engineer
Splunk Administrator/Engineer

Resolution Technologies, Inc. • Georgia

On-site
USD 80,000 - 110,000
Splunk Engineer (Richmond, Charlotte, Pennington)
Splunk Engineer (Richmond, Charlotte, Pennington)

Experis • Richmond (VA)

On-site
USD 58,000 - 96,000
Medical plan
Vision plan
HSA/FSA
+4