Kentro-posted 1 day ago
Full-time • Mid Level
Remote
101-250 employees

Kentro is seeking a dedicated Mid-Level Splunk Analyst to support a high-profile migration effort for a major financial institution. This role focuses on the technical execution of migrating observability workloads from Splunk Observability Cloud (SOC) to Observe Inc. The ideal candidate is a proficient Splunk practitioner who is eager to expand their skillset. While deep expertise in Observe is not required on day one, you must be willing to receive training in Observe and quickly apply that knowledge to translate complex queries and optimize data environments. You will work alongside IT architects and stakeholders to ensure seamless data transfer, query translation (SPL to OPAL), and post-migration optimization in a 24/7 operational environment.

  • Execute the inventorying of dashboards and saved searches via SOC REST APIs to prepare for migration.
  • Manually translate Splunk (SPL) queries into Observe (OPAL) with high semantic fidelity, ensuring critical financial logic (e.g., fraud detection filters) is preserved.
  • Strict Adherence to Security and Standards: Perform all code translations and query logic updates manually or via approved scripts; the use of AI tools (e.g., O11y GPT) is strictly prohibited for this project due to security and accuracy requirements.
  • Assist in configuring data ingestion pipelines using OpenTelemetry agents and intermediaries like Cribl or Fluent Bit.
  • Map data models to Observe’s Snowflake-backed data lake and implement sampling strategies (e.g., 10-20% for traces) during testing phases.
  • Rebuild and validate dashboards in the Observe UI/API for real-time monitoring.
  • Conduct parallel query comparisons and replay scripts to validate data accuracy between the legacy Splunk environment and the new Observe environment.
  • Monitor ingestion health and anomaly detection post-migration to ensure user adoption and reduce alert fatigue.
  • Maintain rigorous Git-versioned documentation of all migration scripts, configurations, and rollback plans.
  • Participate in retrospectives to refine processes for financial audits and scalability.
  • Education – Bachelor’s degree (BA/BS) in Computer Science, Information Systems, Engineering, or a related field.
  • 3–5 years of hands-on experience in Splunk engineering or analysis, specifically focused on event processing and dashboard management.
  • Proven experience working in complex IT environments; prior experience in the financial sector is highly valued due to the low-latency nature of the data.
  • Deep Splunk Proficiency: Strong command of SPL, knowledge management, pre / post indexing data transformations and event management, as this will be the foundation for learning Observe.
  • Scripting Skills: Competency in Python or Bash for API interactions (e.g., Splunk SDK) and automation tasks.
  • Infrastructure as Code (IaC): Familiarity with tools like Terraform or Ansible for configuration management.
  • Ability to explain technical concepts (such as query logic) to non-technical stakeholders or compliance teams.
  • Strong problem-solving skills under pressure, particularly regarding data accuracy in volatile market environments.
  • Splunk Certifications: Certified Power User, Admin, or Architect credentials.
  • Observability Exposure: Prior exposure to Observe Inc. or the OPAL language is a plus, though comprehensive training will be provided.
  • Intermediary Tools: Experience with Cribl or Vector for data forwarding and routing.
  • ITSM Integration: Familiarity with integrating monitoring tools into platforms like ServiceNow or PagerDuty.
  • Active or ability to obtain and maintain Security Clearance is highly preferred.
  • We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more.
  • We invest in our employees – Every employee is eligible for education reimbursement for certifications, degrees, or professional development.
  • Reimbursement amounts may fluctuate due to IRS limitations.
  • We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking.
  • We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.
  • We work hard; we play hard.
  • Kentro is committed to incorporating fun into every day.
  • We dedicate funds for activities – virtual and in-person – e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations.
  • In alignment with our commitment to our communities, we also host and attend charity galas/events.
  • We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service