Sr. Splunk Engineer

ecsfederal

Virginia (MN)

Hybrid

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Everforth ECS is seeking a Sr. Splunk Engineer to join our Professional Services team remotely.

The role focuses on designing, scaling, and operating large‑scale Splunk environments across federal and enterprise contexts, with emphasis on observability, SIEM, and automation. You will design deployments, optimize indexing and searches, write automation (Python, Bash), and work closely with cloud, security, and client stakeholders to deliver reliable, cost‑efficient Splunk solutions, while

Qualifications

  • Deep, hands-on expertise with Splunk Enterprise and Splunk Cloud.
  • Experience designing, deploying, and operating production-scale Splunk environments.
  • Ability to work directly with customers to design and optimize observability and SIEM platforms.
  • Willingness to support domestic or international on-site engagements; U.S. Passport and ability to obtain clearance.

Responsibilities

  • Design, deploy, and maintain Splunk Enterprise and Splunk Cloud environments.
  • Lead customer-facing implementations for observability, security monitoring, and compliance.
  • Develop and optimize data onboarding, ingestion pipelines, indexing strategies, SPL searches, dashboards, alerts, and correlation searches.
  • Design and implement Splunk use cases aligned to customer requirements and mission outcomes.
  • Write scripts and automations (Python, PowerShell, Bash) to improve data ingestion and platform operations.
  • Deploy and operate Splunk across on-premises, cloud, GovCloud, and hybrid environments.
  • Automate deployments and environment management using Terraform, Ansible, CI/CD pipelines.
  • Integrate Splunk with enterprise tooling including endpoint, identity, cloud, and network telemetry sources.
  • Monitor platform health, troubleshoot performance issues, and optimize for scalability and cost efficiency.
  • Provide technical leadership through architecture discussions and reviews.
  • Create and maintain documentation including solution architectures and runbooks.

Skills

Splunk Enterprise
Splunk Cloud
SPL
Data onboarding
Automation (Python)
Linux/Unix
Cloud platforms
Customer-facing

Tools

Terraform
Ansible
CI/CD
Python
PowerShell
Bash

Job description

Everforth ECS is seeking a Sr. Splunk Engineer to join our team remotely. This position is contingent upon contract award.

Are you passionate about designing, scaling, and operating Splunk environments and eager to make an immediate technical impact? Join ECS, a leading provider of cloud, AI, data, and enterprise transformation solutions. In this role, you will implement, optimize, and maintain large‑scale Splunk platforms while contributing to architecture, automation, and client‑facing solutions that improve reliability, performance, and operational efficiency.

We are seeking a Sr. Splunk Engineer to join our Professional Services team. The ideal candidate has deep, hands‑on experience with Splunk Enterprise and/or Splunk Cloud and enjoys working directly with customers to design, deploy, and optimize complex observability and SIEM platforms. You will collaborate with cloud, DevOps, security, and client stakeholders to deliver high‑quality Splunk solutions across a variety of enterprise and federal environments.

Key Responsibilities
  • Design, deploy, and maintain Splunk Enterprise and Splunk Cloud environments, including indexers, search heads, forwarders, and management components.
  • Lead customer‑facing implementations of Splunk for observability, security monitoring, compliance, and operational intelligence.
  • Develop and optimize data onboarding, ingestion pipelines, indexing strategies, SPL searches, dashboards, alerts, and correlation searches.
  • Design and implement Splunk use cases aligned to customer requirements and mission outcomes.
  • Write scripts, automation, and integrations (Python, PowerShell, Bash, etc.) to improve data ingestion, enrichment, monitoring, and platform operations.
  • Deploy and operate Splunk across on‑premises, public cloud (AWS, Azure, GCP), GovCloud, and hybrid environments.
  • Automate deployments and environment management using Terraform, Ansible, CI/CD pipelines, and infrastructure‑as‑code practices.
  • Integrate Splunk with enterprise and security tooling, including endpoint, identity, cloud, and network telemetry sources.
  • Monitor platform health, troubleshoot performance issues, and optimize Splunk environments for scalability, resilience, and cost efficiency.
  • Provide technical leadership through architecture design sessions, best‑practice guidance, and implementation reviews.
  • Create and maintain documentation including solution architectures, deployment patterns, runbooks, and handoff materials.
  • Stay current with Splunk features, apps, and emerging observability and SIEM capabilities.

Salary Range: $140,000 - $190,000

General Description of Benefits

  • Deep, hands‑on expertise with Splunk (Splunk Enterprise and/or Splunk Cloud).
  • Strong experience with SPL, data onboarding, indexer/search head architecture, and performance tuning.
  • Solid understanding of SIEM, observability, logging, metrics, and distributed systems.
  • Experience designing, deploying, and operating production‑scale Splunk environments.
  • Strong scripting and automation skills (Python, PowerShell, Bash, etc.).
  • Experience working in customer‑facing or professional services environments.
  • Strong Linux/Unix, networking, and cloud platform experience (AWS, Azure, GCP).
  • Ability to explain complex technical concepts clearly to both technical and non‑technical stakeholders.
  • Excellent verbal and written communication skills.
  • Willingness and ability to support domestic or international on‑site engagements.
  • U.S. Passport required.
  • Must be eligible to obtain a U.S. Security Clearance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Splunk Platform Engineer Remote Observability & SIEM
Senior Splunk Platform Engineer Remote Observability & SIEM

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 190,000
Senior Splunk & Observability Engineer
Senior Splunk & Observability Engineer

System One • Birmingham (AL)

On-site
USD 120,000 - 180,000
Splunk Cyber Security SME
Splunk Cyber Security SME

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 160,000
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Senior Splunk & Observability Engineer
Senior Splunk & Observability Engineer

System One • Lafayette (LA)

On-site
USD 120,000 - 180,000
Senior Splunk & Observability Engineer
Senior Splunk & Observability Engineer

System One • Knoxville (TN)

On-site
USD 120,000 - 180,000
Splunk Engineer
Splunk Engineer

United States Digital Space LLC • Redmond (WA)

On-site
USD 130,000 - 200,000
Stock options
Discretionary bonuses
Medical, vision, and dental coverage
+4
Senior/Lead Site Reliability Engineer Observability
Senior/Lead Site Reliability Engineer Observability

Tata Consultancy Services • San Jose (CA)

On-site
USD 94,000 - 130,000
Senior Engineer
Senior Engineer

Hobbsnews • Charlotte (NC)

On-site
USD 122,000 - 200,000
Benefits eligible
Paid time off
Annual discretionary award
Senior Engineer
Senior Engineer

Bank of America • Pennington (NJ)

On-site
USD 122,000 - 200,000
Industry-leading benefits
Paid time off
Discretionary incentive eligible