07 Aug
|
Cegeka
|
Chennai
About the job:
As a Splunk Administrator/Engineer, you will play a key role in ensuring the reliability, performance, and continuous evolution of our Splunk setting. You will be responsible for maintaining and troubleshooting the Splunk infrastructure, supporting data onboarding initiatives, developing monitoring and alerting solutions, and collaborating with stakeholders to deliver actionable insights through dashboards and reporting. You will contribute to platform improvements, share technical expertise, and help drive operational excellence across the organization.
Location: Chennai
Work Model: Night Shift USA Alaska Time Zone
What you will do:
- Troubleshoot issues in the Splunk cluster (247), supporting upgrades and patches of the Splunk cluster
- Participate in various projects to support data ingestion (installing forwarders, indexers, search heads, etc.)
- Work with users to create reports, dashboards and troubleshoot issues with data ingestion
- Share your experience and the way you overcame technical and delivery challenges with your colleagues
- Design, implement and maintain alerting solutions using Splunk
- Onboard diverse data sources, build technology add-ons (TAs), and create optimized regular expressions (regex) for field extractions.
What would help you succeed:
- 5+ years hands-on experience working with Splunk/Splunk Cloud and modules like Enterprise Security and ITSI
- Experience onboarding and integrating new data sources into Splunk
- Solid knowledge of SPL (Search Processing Language) and the ability to create and optimize searches, reports, dashboards, and alerts
- Scripting experience - Bash,
Python or any other similar languages will help you in your day-to-day tasks
- Experience with Linux is a must since the platform is hosted on Linux
- Hands-on experience with methodologies like SNMP, Syslogs, Winrm, WMI, SNMP Traps, agent/agentless, API, etc.
- Exposure to CI/CD pipelines (Ansible/Gitlab),
- Capability to develop and improve new/existing automations
- Understanding of networking fundamentals, including TCP/IP, DNS, SSL/TLS, load balancing, and firewall concepts
- Experience working in a production environment with on-call support responsibilities
- Ability to take non-functional requirements into account like security, performance, scalability.
- Cloud platform experience (AWS, Azure, or GCP)
- You feel comfortable in working with ITIL processes.
- Robust problem-solving and analytical skills.
- You are fluent in English, both writing and speaking.
- Robust communication skills and willingness to share knowledge and mentor colleagues
- Minimum of Splunk Certified Enterprise Autonomous Admin or Splunk Certified Enterprise Admin.
Nice to have:
- Basic understanding of security information and event management (SIEM) workflows or Splunk Enterprise Security (ES)
- Experience implementing data onboarding standards, data quality controls, and platform optimization strategies to reduce infrastructure costs
- Practical experience aligning Splunk data models and correlation searches with cyber security frameworks like MITRE ATT&CK;, NIST, or CIS Controls.
- Interest in leveraging AI, AIOps, and automation technologies to improve operational efficiency and incident response
- Proven experience authoring technical runbooks, deployment procedures, and architectural documentation for operations teams.
📌 Splunk Administrator | Night Shift (USA Time Zone) (Chennai)
🏢 Cegeka
📍 Chennai