Sr. Splunk Architect III (6233)

MetroStar SystemsWashington, DC
25d$184,000 - $207,000

About The Position

As a Sr. Splunk Architect III, you'll lead the architectural design, strategy, and enterprise implementation of our Splunk SIEM platform. The Splunk Architect will serve as the primary technical authority, responsible for ensuring scalability, reliability, and alignment of the SIEM with the organization's security, compliance, and operational needs. This role provides strategic guidance to engineering teams, SOC leadership, and business stakeholders. We know that you can't have great technology services without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers. If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below!

Requirements

  • An Active TS security clearance with SCI (active or eligible for SCI)
  • Define the long-term architecture, roadmap, and standards for Splunk Enterprise and Splunk ES.
  • Architect scalable, distributed Splunk environments across on-prem, cloud, or hybrid infrastructure.
  • Lead the SIEM strategy, including detection frameworks, data coverage models, and logging governance.
  • Establish standards for data onboarding, retention, normalization, risk scoring, and use case development.
  • Evaluate new tools, integrations, and technologies that enhance SIEM maturity.
  • Design and oversee Splunk clustering models, search head architecture, indexer scaling, and forwarder deployment patterns.
  • Define Splunk ingestion pipelines, props/transforms, indexing strategy, and data model architecture.
  • Oversee integration of cloud-native logs, security tools, and enterprise applications.
  • Lead platform hardening, access control design, and architectural compliance.

Responsibilities

  • Maintain architecture diagrams, operational guides, and executive reports.
  • Track SIEM improvements, threat trends, and compliance coverage.
  • Plan and optimize Splunk deployment for scalability, reliability, and performance.
  • Ingest logs from diverse sources (firewalls, endpoints, cloud services).
  • Normalize and enrich data for effective detection and analysis.
  • Define data ingestion strategies and index management.
  • Create and refine correlation rules, alerts, dashboards, and reports.
  • Align detection rules with threat intelligence and compliance requirements.

Benefits

  • Performance-based bonuses
  • Company-paid training and/or certifications
  • Referral bonuses

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Industry

Professional, Scientific, and Technical Services

Education Level

No Education Listed

Number of Employees

101-250 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service