Tamkeen Technologies seeks a Senior Splunk Engineer to enhance analytics and monitoring capabilities across IT infrastructure, designing, developing, and maintaining Splunk-based solutions for data collection, analysis, and visualization.
Requirements
- Administer and manage Splunk infrastructure across multiple clients in a multi-tenant MSSP environment.
- Design and implement data onboarding processes including parsing, indexing, and field extractions.
- Manage indexers, search heads, forwarders, and heavy forwarders for optimal performance.
- Troubleshoot and resolve Splunk performance, search latency, and data ingestion issues.
- Develop and optimize SPL queries, dashboards, alerts, and reports.
- Ensure high availability, performance, and scalability of the Splunk platform.
- Maintain forwarders, heavy indexers, search heads, and deployment servers.
- Perform troubleshooting and root cause analysis for log ingestion and performance issues.
- Support client onboarding, use case development, and data source integration.
- Collaborate with SOC analysts, threat hunters, and client security teams to enhance visibility and detection.
- Maintain compliance with internal security policies and relevant regulatory frameworks.
- Implement role-based access control (RBAC), data retention policies, and compliance configurations.
- Work closely with MSSP clients to understand their security monitoring requirements.
- Provide Splunk expertise, troubleshooting, and best practices to internal and external stakeholders.
- Produce documentation for architecture, configurations, processes, and operational runbooks.
Benefits
- Health Insurance
- Retirement Plan
- Paid Time Off
- Life Insurance