Splunk administrator

Job Description

\n

\n

Splunk Architect/Senior Splunk Administrator

\n

Location: London (Hybrid)

\n

Contract: 6 months Initially

\n

IR35: Inside IR35

\n

Overview

\n

We are looking for an experienced Splunk Architect/Senior Splunk Administrator to support and enhance a large-scale Splunk environment. The role requires a strong mix of architectural knowledge and hands-on administration experience across Splunk Enterprise 9.x+ in clustered environments.

\n

Key Skills & Experience

\n

Splunk Enterprise Administration

\n

    \n
  • Splunk environment design and architecture.
  • \n

  • Administration of Indexer and Search Head Clusters.
  • \n

  • Splunk upgrades and platform maintenance.
  • \n

  • Forwarder installation, configuration and troubleshooting.
  • \n

  • Data onboarding, parsing and data quality improvements.
  • \n

  • End-to-end SSL implementation across Splunk components.
  • \n

  • PCRE (Perl Compatible Regular Expressions).
  • \n

  • Data models, data model accelerations and summarised searches.
  • \n

  • Development of knowledge objects, dashboards and alerts.
  • \n

  • Platform health checks, optimisation and troubleshooting.
  • \n

  • Python Scripting (desirable).

\n\n

Splunk Enterprise Security (ES)

\n

    \n
  • ES data models and CIM compliance.
  • \n

  • Correlation searches and notable event management.
  • \n

  • ES content development and administration.

\n\n

Technical Environment

\n

    \n
  • Experience working with Splunk environments managed through CI/CD pipelines.
  • \n

  • Strong Unix/Linux administration skills.
  • \n

  • Windows/PowerShell experience.
  • \n

  • Experience supporting hybrid cloud and on-premise environments.

\n\n

Personal Attributes

\n

    \n
  • Strong analytical and problem-solving skills.
  • \n

  • Excellent communication and stakeholder management.
  • \n

  • Collaborative team player with strong coordination skills.

\n\n

Desirable Experience

\n

    \n
  • Splunk Cloud (SaaS).
  • \n

  • Splunk SOAR.
  • \n

  • Splunk Enterprise Security administration.
  • \n

  • Splunk migration, consolidation or transformation projects.

\n\n

This is an excellent opportunity for a hands-on Splunk specialist who can operate at both technical and architectural levels within a complex enterprise environment.

\n

Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.

Job Details

Company
Lorien
Location
London, UK
Hybrid / Remote Options
Employment Type
Full-time
Posted