More jobs:
Splunk Architect
Job in
Charlotte, Mecklenburg County, North Carolina, 28202, USA
Listed on 2026-09-03
Listing for:
Purple Drive Technologies
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, Security Management & Operations
Job Description & How to Apply Below
Purple Drive
We are seeking an experienced Splunk Architect to design, implement, and lead enterprise-scale Splunk solutions for security monitoring, observability, log management, and analytics. The ideal candidate will have strong expertise in Splunk architecture, data onboarding, search optimization, dashboards, integrations, and large-scale deployments.
Key Responsibilities:
- Design and architect highly scalable, secure, and resilient Splunk Enterprise / Splunk Cloud environments.
- Define Splunk architecture, deployment models, data flows, indexing strategies, and retention policies.
- Lead implementation and migration of enterprise Splunk platforms.
- Develop and optimize SPL queries, dashboards, reports, alerts, and data models.
- Integrate Splunk with enterprise applications, cloud platforms, databases, APIs, and security tools.
- Design solutions for SIEM, security monitoring, IT operations, application monitoring, and observability.
- Implement and manage data ingestion from servers, applications, network devices, cloud services, and security platforms.
- Optimize indexing, search performance, storage, licensing, and platform capacity.
- Establish Splunk security, RBAC, governance, and operational best practices.
- Provide technical leadership, architecture documentation, and design recommendations.
- Troubleshoot complex Splunk performance, ingestion, and search-related issues.
- Collaborate with security, infrastructure, application, cloud, and Dev Ops teams.
Required Skills:
- 10+ years of experience in IT with strong hands-on Splunk experience.
- Strong experience designing enterprise Splunk architecture and deployment models.
- Expertise in Splunk Enterprise, Splunk Cloud, Splunk Enterprise Security (ES).
- Strong proficiency in SPL, dashboards, reports, alerts, and data models.
- Experience with Splunk Indexers, Search Heads, Heavy Forwarders, Universal Forwarders, and Cluster Management.
- Experience with data onboarding, parsing, field extraction, CIM, and source types.
- Strong knowledge of Linux/Unix environments.
- Experience with Python, REST APIs, and automation.
- Experience integrating Splunk with SIEM, cybersecurity, cloud, and monitoring platforms.
- Knowledge of AWS/Azure/GCP and cloud-native architectures.
- Strong understanding of networking, security, authentication, and enterprise infrastructure.
- Preferred Qualifications
- Splunk certifications such as Splunk Enterprise Certified Architect, Splunk Enterprise Security Certified Admin, or Splunk Core Certified Power User.
- Experience with SOAR, ITSI, Observability, or Open Telemetry.
- Experience with Kubernetes, containers, and microservices.
- Experience with Dev Ops, CI/CD, Terraform, or Ansible.
- Strong communication, stakeholder-management, and technical leadership skills.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×