City : Austin
State : Texas
Neos is Seeking a
Senior Splunk Engineer for a contract role with our client in Austin, TX.
***ONSITE - ONLY CANDIDATES CURRENTLY RESIDING IN THE AUSTIN, TX AREA (within 50 miles) WILL BE CONSIDERED***This role is onsite at 6230 E Stassney Ln, Austin, TX 78744No calls, no emails, please respond directly to the "apply" link with your resume and contact details.
Our client is seeking a Senior Splunk Engineers for the ITD Centralized Enterprise Logging Project. Specifically, the worker will be working within the ITD Service Integration & Governance (SIG) Enterprise Architecture - DevSecOps Tools Team.
In this role, the worker will be part of a larger team that will be onboarding hundreds of systems and data sources to Splunk to improve the operational efficiency of ITD. Data sources will include network, cloud, server, and application data sources.
Worker must have hands-on experience using Splunk for operational monitoring and troubleshooting, including creating and executing searches, using dashboards, and supporting alerting workflows. Candidate must be able to support log onboarding/validation and collaborate with ITD teams to ensure reliable data ingestion and actionable alerting.
Minimum Yrs of Experience, Skills, and Qualifications4 years Hands-on experience with Splunk Enterprise and/or Splunk Cloud
4 years Advanced proficiency in Search Processing Language (SPL). Ability to:
- Write efficient, optimized searches
- Use stats, timechart, eval, lookup, transaction, and data model commands
- Tune searches for performance at scale
4 years Experience in data onboarding. Strong skills in:
- Source type design
- Field extraction (regex, props.conf, transforms.conf)
- Timestamp recognition and line breaking
- Index design and strategy
4 years Experience managing Splunk Technology Add-ons (TAs) for data onboarding, normalization, and CIM alignment.
4 years Experience with Common Information Model (CIM) mapping
4 years Ability to design, build, and optimize Splunk dashboards and alerts that provide actionable insights, including KPI-driven visualizations, real-time and scheduled alerts, threshold and anomaly-based detections, alert suppression/tuning to reduce noise, and alignment with operational, security, and business use cases.
Preferred Skills and Qualifications2 years Experience with Cloud-native log source
2 years Experience with security tools (EDR, IAM, firewalls, IDS/IPS)
2 years Splunk Cloud FedRAMP
N/A One or more Splunk certifications (e.g., Architect, Admin, Certified Consultant)
#DICE
#LI_MB