Sr. Splunk Engineer

ECS Tech Inc
Remote

About The Position

Everforth ECS is seeking a Sr. Splunk Engineer to join our team remotely. This position is contingent upon contract award. Are you passionate about designing, scaling, and operating Splunk environments and eager to make an immediate technical impact? Join ECS, a leading provider of cloud, AI, data, and enterprise transformation solutions. In this role, you will implement, optimize, and maintain large‑scale Splunk platforms while contributing to architecture, automation, and client‑facing solutions that improve reliability, performance, and operational efficiency. We are seeking a Sr. Splunk Engineer to join our Professional Services team. The ideal candidate has deep, hands‑on experience with Splunk Enterprise and/or Splunk Cloud and enjoys working directly with customers to design, deploy, and optimize complex observability and SIEM platforms. You will collaborate with cloud, DevOps, security, and client stakeholders to deliver high‑quality Splunk solutions across a variety of enterprise and federal environments.

Requirements

  • Deep, hands‑on expertise with Splunk (Splunk Enterprise and/or Splunk Cloud).
  • Strong experience with SPL, data onboarding, indexer/search head architecture, and performance tuning.
  • Solid understanding of SIEM, observability, logging, metrics, and distributed systems.
  • Experience designing, deploying, and operating production‑scale Splunk environments.
  • Strong scripting and automation skills (Python, PowerShell, Bash, etc.).
  • Experience working in customer-facing or professional services environments.
  • Strong Linux/Unix, networking, and cloud platform experience (AWS, Azure, GCP).
  • Ability to explain complex technical concepts clearly to both technical and non‑technical stakeholders.
  • Excellent verbal and written communication skills.
  • Willingness and ability to support domestic or international on‑site engagements.
  • U.S. Passport required.
  • Must be eligible to obtain a U.S. Security Clearance.

Responsibilities

  • Design, deploy, and maintain Splunk Enterprise and Splunk Cloud environments, including indexers, search heads, forwarders, and management components.
  • Lead customer-facing implementations of Splunk for observability, security monitoring, compliance, and operational intelligence.
  • Develop and optimize data onboarding, ingestion pipelines, indexing strategies, SPL searches, dashboards, alerts, and correlation searches.
  • Design and implement Splunk use cases aligned to customer requirements and mission outcomes.
  • Write scripts, automation, and integrations (Python, PowerShell, Bash, etc.) to improve data ingestion, enrichment, monitoring, and platform operations.
  • Deploy and operate Splunk across on‑premises, public cloud (AWS, Azure, GCP), GovCloud, and hybrid environments.
  • Automate deployments and environment management using Terraform, Ansible, CI/CD pipelines, and infrastructure‑as‑code practices.
  • Integrate Splunk with enterprise and security tooling, including endpoint, identity, cloud, and network telemetry sources.
  • Monitor platform health, troubleshoot performance issues, and optimize Splunk environments for scalability, resilience, and cost efficiency.
  • Provide technical leadership through architecture design sessions, best‑practice guidance, and implementation reviews.
  • Create and maintain documentation including solution architectures, deployment patterns, runbooks, and handoff materials.
  • Stay current with Splunk features, apps, and emerging observability and SIEM capabilities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service