Splunk Architect

TCS•Charlotte, NC

About The Position

Splunk Architect Job Summary We are seeking an experienced Splunk Architect to design, implement, and lead enterprise-scale Splunk solutions for security monitoring, observability, log management, and analytics. The ideal candidate will have strong expertise in Splunk architecture, data onboarding, search optimization, dashboards, integrations, and large-scale deployments.

Requirements

  • 10+ years of experience in IT with strong hands-on Splunk experience.
  • Strong experience designing enterprise Splunk architecture and deployment models.
  • Expertise in Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security (ES).
  • Strong proficiency in SPL, dashboards, reports, alerts, and data models.
  • Experience with Splunk Indexers, Search Heads, Heavy Forwarders, Universal Forwarders, and Cluster Management.
  • Experience with data onboarding, parsing, field extraction, CIM, and source types.
  • Strong knowledge of Linux/Unix environments.
  • Experience with Python, REST APIs, and automation.
  • Experience integrating Splunk with SIEM, cybersecurity, cloud, and monitoring platforms.
  • Knowledge of AWS/Azure/GCP and cloud-native architectures.
  • Strong understanding of networking, security, authentication, and enterprise infrastructure.

Nice To Haves

  • Splunk certifications such as Splunk Enterprise Certified Architect, Splunk Enterprise Security Certified Admin, or Splunk Core Certified Power User.
  • Experience with SOAR, ITSI, Observability, or OpenTelemetry.
  • Experience with Kubernetes, containers, and microservices.
  • Experience with DevOps, CI/CD, Terraform, or Ansible.
  • Strong communication, stakeholder-management, and technical leadership skills.

Responsibilities

  • Design and architect highly scalable, secure, and resilient Splunk Enterprise / Splunk Cloud environments.
  • Define Splunk architecture, deployment models, data flows, indexing strategies, and retention policies.
  • Lead implementation and migration of enterprise Splunk platforms.
  • Develop and optimize SPL queries, dashboards, reports, alerts, and data models.
  • Integrate Splunk with enterprise applications, cloud platforms, databases, APIs, and security tools.
  • Design solutions for SIEM, security monitoring, IT operations, application monitoring, and observability.
  • Implement and manage data ingestion from servers, applications, network devices, cloud services, and security platforms.
  • Optimize indexing, search performance, storage, licensing, and platform capacity.
  • Establish Splunk security, RBAC, governance, and operational best practices.
  • Provide technical leadership, architecture documentation, and design recommendations.
  • Troubleshoot complex Splunk performance, ingestion, and search-related issues.
  • Collaborate with security, infrastructure, application, cloud, and DevOps teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service