Role: Splunk Engineer
Location: Austin, TX, Local Candidates Only to Austin, TX - Must reside within 25 miles of Austin, TX
Duration: Long-term
Must have:
Hands-on experience with Splunk Enterprise and/or Splunk Cloud
Advanced proficiencies in Search Processing Language (SPL).
Ability to write efficient, optimized searches and use stats, timechart, eval, lookup, transaction, and data model commands
Experience in data onboarding. Strong skills in:
• Source type design
• Field extraction (regex, props.conf, transforms.conf)
• Timestamp recognition and line breaking
Index design and strategy
Experience managing Splunk Technology Add-ons (TAs) for data onboarding, normalization, and CIM alignment.
Experience with Common Information Model (CIM) mapping
Ability to design, build, and optimize Splunk dashboards and alerts that provide actionable insights, including KPI-driven visualizations, real-time and scheduled alerts, threshold and anomaly-based detections, alert suppression/tuning to reduce noise, and alignment with operational, security, and business use cases.
Preferred Skills and Qualifications
- Experience with Cloud-native log source
Experience with security tools (EDR, IAM, firewalls, IDS/IPS)
Splunk Cloud FedRAMP
N/A One or more Splunk certifications (e.g., Architect, Admin, Certified Consultant)