09 Aug
|
SPG Consulting
|
Pune
09 Aug
SPG Consulting
Pune
(JD) – Splunk Architect
Job Title
Splunk Architect
Job Summary
The Splunk Architect is responsible for designing, implementing, and optimizing Splunk Enterprise environments to support enterprise monitoring, security analytics, log management, and operational intelligence. The role involves architecture planning, scalability, performance tuning, integrations, and governance across complex IT infrastructures.
Key Responsibilities
- Design and architect scalable Splunk Enterprise infrastructure and deployment models
- Lead implementation of Splunk solutions for monitoring, security, and analytics
- Configure indexers, search heads, forwarders, clustering, and deployment servers
- Develop data onboarding strategies and parsing configurations
- Optimize Splunk performance, storage, and search efficiency
- Create dashboards, alerts, reports, and advanced visualizations
- Integrate Splunk with cloud, SIEM, DevOps, and third-party tools
- Support security use cases including threat monitoring and incident analysis
- Ensure platform availability, scalability, backup, and disaster recovery planning
- Define governance, RBAC, data retention, and compliance standards
- Mentor engineering teams and provide technical leadership
- Collaborate with infrastructure, security, and application teams
Required Skills
- Robust expertise in Splunk Enterprise architecture and administration
- Experience with Splunk clustering, indexing, and distributed deployments
- Knowledge of SIEM, log management, and observability concepts
- Hands-on experience with SPL (Search Processing Language)
- Understanding of Linux/Unix administration and scripting
- Experience with cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud
- Familiarity with DevOps and automation tools
- Strong troubleshooting and performance tuning skills
- Knowledge of cybersecurity frameworks and compliance standards
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or related field
- 6–12 years of IT experience with 3+ years in Splunk architecture
- Splunk certifications preferred:
- Splunk Enterprise Certified Architect
- Splunk Core Certified Consultant
Preferred Experience
- Experience implementing enterprise SIEM solutions
- Exposure to SOC operations and security monitoring
- Experience with Kubernetes, containers, and cloud-native monitoring
- Knowledge of CI/CD and Infrastructure as Code (IaC)
- Experience integrating Splunk with security tools and ticketing systems
Key Metrics
- Platform uptime and stability
- Search and indexing performance
- Data onboarding efficiency
- Incident detection and response improvement
- Infrastructure scalability and optimization
Common Tools & Technologies
- Splunk Enterprise
- Splunk Enterprise Security
- Linux
- Docker
- Kubernetes
- Jenkins
- Terraform
📌 Splunk Architect (Pune)
🏢 SPG Consulting
📍 Pune