Summary The Senior Technical Lead Splunk role is aimed at overseeing and enhancing Splunk/SIEM platforms in large enterprise settings, ultimately ensuring efficient operations and strong security posture.
Main Responsibilities
- Support and administer Splunk/SIEM platforms with 7-15 years of hands-on experience.
- Perform log onboarding, source integration, parser creation, CIM mapping, and ingestion pipeline management.
- Deploy, configure, administer, and optimize Splunk components: manage index lifecycle, retention policies, and storage optimization.
- Optimize searches, dashboards, reports, alerts, and correlation searches for performance and scalability.
- Implement and maintain SPL-based monitoring and operational dashboards.
- Support platform migrations and environment expansion initiatives.
- Provide Distributed Enterprise level support for Splunk Enterprise and Splunk ES.
- Manage Splunk upgrades, patches, and release management.
- Conduct security patching and vulnerability remediation across enterprise Splunk environments.
- Perform root cause analysis and complex problem resolution in mission-critical environments.
Key Requirements
- 7-15 years of hands-on experience with Splunk/SIEM platforms.
- Solid experience in Splunk Enterprise and Splunk Enterprise Security (ES) administration.
- Deep understanding of Splunk architecture and CIM onboarding.
- Hands-on experience with troubleshooting, log onboarding, and performance optimization.
- Experience conducting platform migrations and managing upgrades.
- Minimum of two Splunk certifications (e.g., Splunk Core Certified Admin).
- Strong scripting and automation experience with Terraform and Ansible.
- Experience administering Linux-based environments.
Nice to Have
- Experience with Splunk SOAR administration and playbook development.
- Cribl Stream administration experience.
- Proficiency in Python, Bash, or PowerShell scripting.
- Experience with cloud platforms (AWS, Azure, GCP).
- Knowledge of MITRE ATT&CK; framework.
- ITIL Foundation certification.
Other Details
- Category: Large enterprise environments.
- Reporting Structure: Direct support for Cyber Security operations and SOC environments.
- Remote
- Looking for immediate joiner only
📌 Senior Technical Lead Splunk (India)
🏢 Emagine
📍 India