GCYber is seeking a Senior Splunk Administrator to support a high-profile government customer. This is a hands-on administration role responsible for data ingestion, dashboard development, and resolving issues when data is missing, delayed, duplicated, or incorrectly parsed. As the Senior Splunk Administrator, you will administer and monitor an enterprise Splunk environment, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, deployers, cluster managers, and monitoring consoles. You will troubleshoot missing, delayed, duplicated, incorrectly parsed, or incorrectly routed data across the complete ingestion path. You will also configure and maintain Splunk inputs, outputs, indexes, sourcetypes, routing, filtering, timestamp extraction, and event parsing. Additionally, you will build and maintain Splunk dashboards, reports, alerts, and saved searches that provide useful operational and cybersecurity visibility. You will work with stakeholders to define dashboard requirements, identify the right data, and present results in a clear and actionable format. You will develop and optimize SPL searches that support dashboards, data validation, troubleshooting, trend analysis, and operational reporting. You will diagnose issues involving forwarders, blocked queues, certificates, network connectivity, indexing, permissions, dashboards, and search logic.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior