Splunk Engineer

GTTAuburn, AL
Remote

About The Position

This role focuses on designing, implementing, and optimizing Splunk Enterprise and Splunk Cloud architectures — including indexers, search heads, forwarders, and deployment servers — to support security monitoring, log management, and operational analytics. This role can be 100% remote or onsite; there is no preference.

Requirements

  • Experience in Splunk architecture, including indexers, search heads, forwarders, and deployment server.
  • Experience developing Splunk dashboards, reports, alerts, tuning alerts, and saved searches.
  • Experience onboarding and normalizing log sources from infrastructure, applications, cloud platforms, and security tools.
  • Experience building pipelines to parse, normalize, enrich, and route data to Splunk.
  • Proficiency with Splunk Search Processing Language (SPL), data models, and role-based access controls.
  • Knowledge of Security Information and Event Management (SIEM) concepts, security monitoring, and threat detection use cases.
  • Networking fundamentals, including Transmission Control Protocol/User Datagram Protocol (TCP/UDP), Transport Layer Security (TLS), syslog transport, firewall ports, and common transport issues, as well as system log analysis.
  • Experience in Linux and Windows administration.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or other related field required.
  • Must hold one or more of the following certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or a Splunk Enterprise Security certification.
  • 5 years of experience implementing, managing, and configuring Splunk Enterprise or Splunk Cloud.

Nice To Haves

  • Advanced Splunk certifications, such as Splunk Certified Architect or Splunk Enterprise Security Certified Admin.
  • Experience with Splunk Enterprise Security or Security Orchestration, Automation, and Response (SOAR) platforms.
  • Scripting experience (Python, PowerShell, or Bash) for automation and data onboarding.
  • Experience supporting SOC operations in government, higher education, or critical infrastructure environments.

Responsibilities

  • Design, implement, and optimize Splunk Enterprise and Splunk Cloud architectures — including indexers, search heads, forwarders, and deployment servers — to support security monitoring, log management, and operational analytics.
  • Develop and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to partner and mission requirements.
  • Integrate data sources into Splunk, including infrastructure, cloud, application, and security technologies.
  • Build and maintain pipelines to parse, normalize, enrich, and route data to Splunk.
  • Support use case development for threat detection, incident response, compliance monitoring, and operational visibility.
  • Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures.
  • Administer role-based access controls and monitor the health, performance, and availability of the Splunk environment.
  • Distill complex technical concepts into accessible explanations for analysts, leadership, and non-technical partners.
  • Utilize strong communication and presentation skills.
  • Recognize, analyze, and solve a variety of problems.

Benefits

  • Medical, Vision, and Dental Insurance Plans
  • 401k Retirement Fund
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service