Splunk Architect

Links Technology Solutions, Inc.

Schaumburg, Northern (IL, KY)

Hybrid

USD 25,000 - 41,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health Insurance
Dental Insurance
Vision Insurance
401K Matching
Remote work in Costa Rica

Job summary

Links Technology Solutions, Inc. is seeking a Certified Splunk Architect to design, implement, and maintain a large-scale Splunk environment. The role focuses on Splunk Enterprise, Enterprise Security, and SOAR for automation in a hybrid security operations context.

The candidate will lead detection engineering efforts, build actionable dashboards, and provide SME guidance to Security, Operations and Business teams, while being remotely located in Costa Rica.

Qualifications

  • Must hold current Splunk Certified Architect (preferred: Splunk Certified Core Consultant).
  • 3+ years in Splunk with at least 1 year in detection engineering.
  • Proficient in Python/Bash for deployment automation and API integration.
  • Hands-on experience with Splunk Cloud/AWS/Azure/GCP deployments.

Responsibilities

  • Design, implement, and maintain large-scale Splunk environments.
  • Develop and update custom detection rules and integrate with 3rd party tools.
  • Architect ES solutions to deliver actionable security use cases.
  • Automate pre/post ticket workflows using Splunk SOAR and related tools.
  • Lead technical initiatives and mentor Security, Operations and Business teams.

Skills

Communication
Technical Leadership
Problem Solving

Tools

Python
Bash
Splunk Enterprise
Splunk ES
Splunk SOAR
AWS
Azure
GCP
rsyslog

Job description

Certified Splunk Architect Overview

We're looking for an intelligent, imaginative, highly skilled and driven Certified Splunk Architect to work alongside some of the best in the industry in a team focused setting. We are creating with the Splunk environment never before seen Security, Operations and Business use cases. You will design, implement, and maintain a complex, large-scale Splunk environment. This role requires deep expertise across the entire Splunk Enterprise and Cloud platforms (Hybrid). The successful candidate will have Splunk Enterprise Security, specifically detection engineering expertise.

Key Responsibilities
  • Detection Engineering: Build and update custom detection rules, leverage and integrate detections with 3rd party tools (including Splunk Behavioral Analytics), all within a Risk Based Alerting format.
  • Solution Development: Architect and implement specialized Splunk solutions, particularly Splunk Enterprise Security (ES), to deliver actionable insights and use cases.
  • Automation: Design and build workflows for pre and post ticket automation, using Splunk SOAR and other tools.
  • Reporting: Create the next level of security detection readiness executive and engineer dashboard(s).
  • Performance Optimization: Conduct regular health checks and performance tuning of the Splunk environment, optimizing search latency, data processing, and resource utilization across the infrastructure.
  • Technical Leadership: Serve as a subject matter expert (SME) for all Splunk technologies, providing technical leadership, documentation, and mentorship to Security, Operations and Business teams.
Required Qualifications
  • Certification: Must possess current, active certification as a Splunk Certified Architect (preferred: Splunk Certified Core Consultant).
  • Experience: 3+ years of progressive experience working with the Splunk platform; at least 1 year dedicated detection engineering.
  • Scripting & Automation: Proficient in scripting languages (Python, Bash) for deployment automation, configuration management, and API integration.
  • Cloud Proficiency: Hands-on experience deploying and managing Splunk in AWS, Azure, or GCP environments, including understanding of relevant cloud services/sources of security data.
  • Technical Depth: Splunk Deployment Servers, Splunk Data Collection Nodes, Splunk intermediary forwarders, Splunk DB Connect, Splunk Universal Forwarders (Linux, Solaris, Windows, Mac), rsyslog collectors, data processing pipeline (preferred ingest/edge processor); Splunk SOAR.
  • Communication: Excellent written and verbal communication skills, with the ability to articulate complex technical concepts to both business and technical audiences.
Benefits of the Splunk Architect

Health, Dental, Vision Insurance Matching 401K REMOTE role - You MUST be located in Costa Rica Long Term Contract Paying up to $30/hr #IND1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Splunk Engineer
Splunk Engineer

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Remote Splunk Architect: ES & SOAR Leader
Remote Splunk Architect: ES & SOAR Leader

Links Technology Solutions, Inc. • Schaumburg (IL), Northern (KY)

Hybrid
USD 25,000 - 41,000
Health Insurance
Dental Insurance
Vision Insurance
+2
Splunk Engineer/Architect
Splunk Engineer/Architect

Piper Companies • Morrisville (NC)

On-site
USD 140,000 - 180,000
Comprehensive benefits
Splunk Administrator/Engineer
Splunk Administrator/Engineer

Resolution Technologies, Inc. • Georgia

On-site
USD 80,000 - 110,000
Splunk Architect (Secret Cleared)
Splunk Architect (Secret Cleared)

Verigent • Doral (FL)

On-site
Splunk Engineer
Splunk Engineer

RapidSoft Corp • Reston (VA)

On-site
USD 90,000 - 120,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Splunk Architect
Splunk Architect

Sonoma Consulting Inc. • Boston (MA)

On-site
USD 100,000 - 130,000
Splunk SIEM Security Engineer/Architect
Splunk SIEM Security Engineer/Architect

WaveStrong, Inc. • Los Angeles (CA)

On-site
USD 100,000 - 130,000