The Splunk Cloud Administrator will support IT and cybersecurity operations for the CDC by designing, implementing, and managing Splunk Enterprise environments across on-premises, MSP, and cloud infrastructures. This role enables enterprise security monitoring, data integration, automation, and compliance activities for the CDC’s Cybersecurity Program Office (CSPO). Write and optimize advanced SPL queries for monitoring, reporting, and troubleshooting. Manage data ingestion, indexing, and forwarding for internal teams and customers from cloud, server, application, and endpoint sources. Configure and support Splunk forwarders though Splunk deployment servers in conjunction with Syslog-NG, Cribl, AWS Lambda, and Azure Function Apps for reliable data intake. Create dashboards, visualizations, reports, and alerts for both technical and business users. Automate operational tasks and data processes using Python, Bash, and PowerShell. Support Splunk environments in both self-hosted and Splunk GovCloud deployments. Integrate Splunk with enterprise platforms including Archer, ServiceNow, Azure, and AWS. Troubleshoot platform infrastructure, networking, and security-related issues impacting data visibility and performance. Troubleshoot and implement role-base access controls with SAML in Splunk Custom app development, vetting, and deployment to on-premises and Splunk Cloud instances Apply Splunk AI Toolkit for use cases such as anomaly detection, forecasting, clustering, and predictive analytics. Contribute to monitoring and visibility for AI application stacks, including LLMs and related infrastructure, when needed.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed