Haystack
← Back to Jobs
Technology

Splunk Platform Engineer at Charlotte, NC/Pennington, NJ/Richmond, VA

SkylineIT SolutionsCharlotte, NC🇺🇸United StatesPosted 17 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Role: Splunk Platform Engineer
Location: Charlotte, NC/Pennington, NJ,Richmond, VA Hybrid 3-4 days onsite a week
Contract(1 year) with possible extension
 
The engineer will act as a trusted platform owner, ensuring Splunk availability, scalability, and reliability while partnering closely with Information Security, SOC, architecture, engineering, and operations teams.
Splunk Platform Operations Production Stability
• Own end-to-end production support for a highly distributed Splunk Enterprise and Splunk Cloud environment, including search head clusters, indexer clusters, deployers, deployment servers, and forwarders
• Ensure high availability, performance, and resiliency of the Splunk platform supporting security and operational use cases
• Lead incident response, troubleshooting, root cause analysis (RCA), and service restoration for Splunk and Cribl platforms
• Proactively identify risks, capacity constraints, and performance bottlenecks; implement preventive and tuning measures
Security Log Ingestion SIEM Enablement
• Serve as a key technical enabler for Information Security and SOC teams, ensuring timely, accurate, and reliable ingestion of security logs
• Onboard and normalize new data sources, supporting CIM compliance, field normalization, and SIEM best practices
• Tune ingestion pipelines using props.conf and transforms.conf, index-time and search-time optimizations
• Build and support dashboards, searches, and alerts that enable threat detection, investigations, and reporting
Cribl Data Pipeline Management
• Administer and support the Cribl environment for data routing, filtering, enrichment, and cost optimization
• Ensure data integrity, reliability, and performance across Splunk ingestion pipelines
• Collaborate with architecture teams on data flow strategies and onboarding standards
Governance, Documentation Compliance
• Develop and maintain runbooks, SOPs, installation guides, and operational documentation
• Adhere to change management, incident management, and SLA commitments using ITSM tools
5+ years of hands-on experience administering large-scale Splunk Enterprise or Splunk Cloud environments
Strong expertise in:
o Indexer clustering and search head clustering
o Universal and heavy forwarder architectures
o SmartStore / S3-compatible object storage
o SPL, search optimization, summary indexing, data model acceleration
Deep experience with security log ingestion and SIEM use cases
Proven ability to lead production incidents, perform RCA, and drive preventive solutions
Strong Linux administration skills and experience managing Splunk configuration and apps
Experience working in 24x7 production environments with high availability expectations
Excellent written and verbal communication skills, with the ability to engage senior technical and business stakeholders
Success in this position requires:
• A production owners mindset
• Deep technical credibility in Splunk and data pipelines
• Ability to operate calmly and decisively during high-severity security and platform incidents
• Strong partnership with Information Security, where Splunk availability and data quality are mission-critical to protecting the bank.
• Splunk certifications such as Enterprise Admin or Enterprise Architect
• Experience with Splunk Enterprise Security (ES) and SOAR (Phantom or equivalent)
• Exposure to cloud logging and security architectures (AWS, Azure, Google Cloud Platform)
• Knowledge of Red Hat Enterprise Linux and Windows Server administration
• Experience with monitoring, APM, and event management tools
• Strong understanding of security, network, system, and database operations
• Ability to balance multiple priorities in a fast-paced, enterprise production environment
 
Hybrid - 4 days onsite, 1 day remote for first 6 months and
Hybrid - 3 days onsite, 2 days remote after 6 months
CHARLOTTE North Carolina PENNINGTON New Jersey
 
 
 

Warm Regards,

Charan Kumar | Skyline IT

Email id:

Linkedin:

website:
Company Address :3124 STONELAKE RDG Carrollton, TX 75010
 
 
 

Skills

AWS
Splunk
Azure
Data Pipeline
Google Cloud

Similar jobs