Unlock Full Resume Report

New offer - be the first one to apply!

September 17, 2026

Senior Splunk Technical Lead

Senior • Remote

New Delhi, DL, India

Quick Facts

  • Role: Senior Technical Lead (Splunk)

  • Focus: Splunk/SIEM platform administration, security patching, monitoring, and SOC support

  • Work style: Remote

Description

Oversee and enhance enterprise Splunk/SIEM platforms to ensure efficient operations and a strong security posture. Lead log onboarding (source integration, parsers, CIM mapping) and optimize Splunk components, searches, and SPL-based monitoring. Provide distributed enterprise-level support for Splunk Enterprise and Splunk ES, including upgrades, patching, migrations, and complex troubleshooting.

Responsibilities

  • Administer and optimize Splunk/SIEM platforms in large enterprise environments

  • Perform log onboarding: source integration, parser creation, CIM mapping, and ingestion pipeline management

  • Configure and optimize Splunk components (index lifecycle, retention policies, storage optimization)

  • Optimize searches, dashboards, reports, alerts, and correlation searches for performance and scalability

  • Implement and maintain SPL-based monitoring and operational dashboards

  • Support platform migrations and environment expansion initiatives

  • Provide Distributed Enterprise level support for Splunk Enterprise and Splunk ES

  • Manage Splunk upgrades, patches, and release management

  • Conduct security patching and vulnerability remediation across enterprise Splunk environments

  • Perform root cause analysis and resolve complex problems in mission-critical environments

Requirements

  • 7–15 years of hands-on experience with Splunk/SIEM platforms

  • Strong administration experience with Splunk Enterprise and Splunk Enterprise Security (ES)

  • Deep understanding of Splunk architecture and CIM onboarding

  • Hands-on experience with troubleshooting, log onboarding, and performance optimization

  • Experience conducting platform migrations and managing upgrades

  • Minimum of two Splunk certifications (e.g., Splunk Core Certified Admin)

  • Strong scripting and automation experience with Terraform and Ansible

  • Experience administering Linux-based environments

Nice to Have

  • Splunk SOAR administration and playbook development

  • Cribl Stream administration experience

  • Python, Bash, or PowerShell scripting

  • Cloud platforms: AWS, Azure, GCP

  • Knowledge of the MITRE ATT&CK framework

  • ITIL Foundation certification

Benefits

  • Remote

  • Immediate joiner only

Similar jobs you might like