About the job
At Tamkeen Technologies, we are seeking a skilled Senior Splunk Engineer to elevate our analytics and monitoring capabilities across our IT infrastructure. In this pivotal role, you will design, develop, and maintain innovative Splunk-based solutions that facilitate data collection, analysis, and visualization to provide crucial security and operational insights. You will collaborate closely with diverse teams to implement best practices in data ingestion, dashboard creation, and alert configuration, aligning with our organizational objectives. If you possess a robust background in Splunk and a passion for data analytics, we invite you to apply and become part of our forward-thinking team.
Key Responsibilities
- Administer and manage Splunk infrastructure across multiple clients in a multi-tenant MSSP environment.
- Design and implement data onboarding processes, including parsing, indexing, and field extractions.
- Oversee indexers, search heads, forwarders, and heavy forwarders for optimal performance.
- Troubleshoot and resolve Splunk performance, search latency, and data ingestion issues.
- Develop and optimize SPL queries, dashboards, alerts, and reports.
- Ensure high availability, performance, and scalability of the Splunk platform.
- Maintain forwarders, heavy indexers, search heads, and deployment servers.
- Conduct troubleshooting and root cause analysis for log ingestion and performance challenges.
- Support client onboarding, use case development, and data source integration.
- Collaborate with SOC analysts, threat hunters, and client security teams to enhance visibility and detection.
- Maintain compliance with internal security policies and relevant regulatory frameworks.
- Implement role-based access control (RBAC), data retention policies, and compliance configurations.
- Work closely with MSSP clients to understand their security monitoring needs.
- Provide Splunk expertise, troubleshooting, and best practices to internal and external stakeholders.
- Produce comprehensive documentation for architecture, configurations, processes, and operational runbooks.
