Splunk Architect - Enterprise Security

Vinmar Digital Analytics

United States

Remote

USD 150,000 - 230,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Vinmar Digital Analytics seeks a senior Splunk Architect to design, implement, and maintain a large-scale Splunk Enterprise and Splunk ES environment. You will lead architectural strategy, ensure stability, scalability, and security, and guide complex deployments.

This role requires expert Splunk ES knowledge and hands-on experience with security use cases and integration with security tools. Responsibilities include leading HA deployments, designing indexer and search head clusters, onboarding

Qualifications

  • 8+ years IT experience with 5+ years in Splunk Enterprise/ES architecture in an enterprise
  • Expert-level knowledge of Splunk deployment methodologies including multi-site clustering, SmartStore, and high availability design
  • Proven experience with security use case development, threat modeling, and building effective correlation searches within Splunk ES
  • Proficiency in Python, Bash, or PowerShell for deployment automation
  • Deep understanding of Linux/Windows OS and cloud infrastructure (AWS, Azure, or GCP)

Responsibilities

  • Lead the Architectural Lead for Splunk Enterprise and Splunk ES in HA, distributed, and cloud/hybrid environments
  • Define, design, and maintain long-term Splunk architecture including indexer clusters, search head clusters, deployment servers, and heavy/universal forwarders
  • Conduct capacity planning and performance optimization for all Splunk components
  • Architect security dashboards, data models, and analytics to support threat detection and investigations
  • Oversee data onboarding aligned with the CIM and enforce security hardening and change control processes

Skills

Splunk architecture
SPL
Python
Bash
PowerShell
Linux/Windows
Cloud (AWS/Azure/GCP)
Security use cases
Automation scripting

Tools

Ansible
Terraform
SOAR
ITSI

Job description

Job Summary

Vinmar is seeking a highly experienced and certified Splunk Architect to design, implement, and maintain our large-scale, distributed Splunk Enterprise and Splunk Enterprise Security (ES) environment. The ideal candidate will be a technical leader, responsible for defining the long-term Splunk architectural strategy, ensuring platform stability, scalability, and security posture in line with organizational cybersecurity objectives. This role requires deep expertise in Splunk Enterprise Security and a proven track record of successful, complex deployments.

Key Responsibilities
Architecture & Design
  • Serve as the Architectural Lead for the Splunk Enterprise and Splunk Enterprise Security (ES) platforms in high-availability, distributed, and cloud/hybrid environments.
  • Define, design, and maintain the long-term Splunk architecture, including indexer clusters, search head clusters, deployment servers, and heavy/universal forwarders, ensuring optimal performance and resilience.
  • Conduct capacity planning and performance optimization reviews for all Splunk components.
  • Architect and guide the design of security-focused dashboards, data models, and advanced analytics to support threat detection, incident response, and forensic investigations within Splunk ES.
Enterprise Security & Platform Management
  • Drive the implementation and configuration of Splunk Enterprise Security (ES), including correlation searches, notable events, risk scoring, and threat intelligence framework integration.
  • Oversee the onboarding and normalization of diverse data sources (OS logs, network logs, application logs, cloud service logs, etc.) into Splunk, ensuring strict alignment with the Splunk Common Information Model (CIM).
  • Develop, implement, and enforce configuration management, security hardening, and change control processes for the Splunk platform.
  • Utilize Splunk Search Processing Language (SPL) expertise to create complex and efficient queries, reports, and data visualizations for various security use cases.
  • Integrate Splunk with other security tools and systems (e.g., SOAR, CMDB, SIEMs) via APIs and custom development.
Leadership & Mentorship
  • Provide technical leadership and mentorship to Splunk administrators, engineers, and security analysts on best practices for platform usage, SPL, CIM, and ES features.
  • Create and maintain comprehensive documentation, including conceptual designs, reference architectures, and operational runbooks.
  • Collaborate with cybersecurity leadership and stakeholders to align the Splunk roadmap with overall security and business objectives.
Required Qualifications & Expertise
Experience
  • Minimum of 8+ years of progressive IT experience, with at least 5 years focused specifically on Splunk Enterprise/ES architecture and engineering in an enterprise environment.
  • Expert-level knowledge of Splunk deployment methodologies, including multi-site clustering, SmartStore, and high-availability design.
  • Proven experience with security use case development, threat modeling, and building effective correlation searches within Splunk ES.
  • Proficiency in scripting languages (e.g., Python, Bash, or PowerShell) for automation of deployment and maintenance tasks.
  • Deep technical understanding of core security concepts, network protocols, server operating systems (Linux/Windows), and cloud infrastructure (AWS, Azure, or GCP).
Mandatory Certifications

Candidates must possess all of the following current Splunk certifications:

  • Splunk Enterprise Certified Architect (Demonstrates expertise in complex deployment and sizing).
  • Splunk Enterprise Security Certified Admin (Demonstrates mastery of the ES premium solution).
  • Splunk Core Certified Consultant (Highly preferred as a demonstration of holistic expertise).
Preferred Qualifications
  • Experience with Splunk SOAR (Security Orchestration, Automation, and Response) or Splunk ITSI (IT Service Intelligence).
  • Relevant industry certifications such as CISSP, CISM, or CompTIA Security+.
  • Experience with Infrastructure as Code (IaC) tools like Ansible or Terraform for managing Splunk deployments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Senior Splunk Architect – Enterprise Security & Cloud HA
Senior Splunk Architect – Enterprise Security & Cloud HA

Vinmar Digital Analytics • United States

Remote
USD 150,000 - 230,000
Splunk Engineer
Splunk Engineer

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Splunk Engineer
Splunk Engineer

RapidSoft Corp • Reston (VA)

On-site
USD 90,000 - 120,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Senior SIEM Engineer (Splunk)
Senior SIEM Engineer (Splunk)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate, LLC. • Richmond (VA)

On-site
USD 110,000 - 140,000
Splunk Administrator/Engineer
Splunk Administrator/Engineer

Resolution Technologies, Inc. • Georgia

On-site
USD 80,000 - 110,000
Splunk Subject Matter Expert (SME) & Enterprise Monitoring Engineer
Splunk Subject Matter Expert (SME) & Enterprise Monitoring Engineer

Empower Professionals Inc - Talent & IT Services • Frisco (TX)

On-site
USD 120,000 - 150,000
Splunk engineer
Splunk engineer

Q1 Technologies, Inc. • Jacksonville (FL)

On-site
USD 100,000 - 130,000