Splunk Administrator Security Clearance
Job in
Des Moines, Polk County, Iowa, 50301, USA
Listed on 2026-07-13
Listing for:
Belcan, LLC
Full Time
position Listed on 2026-07-13
Job specializations:
-
IT/Tech
Cybersecurity, Systems Administrator, Cloud Computing: Infrastructure & Operations
Job Description & How to Apply Below
Job Summary:
The Splunk & Microsoft 365 Administrator will be responsible for managing, monitoring, and optimizing the enterprise Splunk platform and Microsoft 365 environment. The role includes administration of Microsoft Exchange Online, Teams, SharePoint Online, One Drive, Azure AD/Entra , and Microsoft security solutions, while ensuring the reliability, security, and performance of Splunk infrastructure used for log management, monitoring, and security analytics. The ideal candidate should possess strong troubleshooting skills, experience supporting enterprise collaboration platforms, and expertise in SIEM, monitoring, and cloud administration.
Job Duties:
* Platform Management
* Install, configure, and maintain Splunk Enterprise and Splunk Universal Forwarders.
* Manage Splunk indexers, search heads, deployment servers, cluster masters, and heavy forwarders.
* Oversee Splunk architecture for performance, scalability, and high availability.
* Apply patches, upgrades, and version migrations while ensuring platform stability.
* Data Onboarding & Parsing
* Onboard new data sources (syslog, APIs, agents, cloud connectors, Windows/Linux logs).
* Create and maintain inputs.conf, props.conf, and transforms.conf.
* Develop field extractions, source types, timestamps, and line-breaking rules.
* Ensure proper data normalization and schema alignment (CIM compliance where needed).
* Search, Dashboards, and Visualization
* Build and optimize SPL queries for dashboards, alerts, reports, and scheduled searches.
* Develop enterprise-grade dashboards and visualizations for IT operations, security, and business teams.
* Tune saved searches for performance and resource efficiency.
* Monitoring, Alerting & Incident Support
* Create operational and security alerts aligned with business/service requirements.
* Monitor ingestion volumes, license usage, disk utilization, and system health.
* Troubleshoot ingestion delays, search performance issues, missing data, and forwarder connectivity.
* Support incident management teams by providing log insights and analysis.
* Security & Compliance
* Manage authentication/authorization (LDAP/AD, SAML, RBAC).
* Implement access controls, user roles, and knowledge object permissions.
* Ensure compliance with audit requirements and log retention policies.
* Maintain data integrity and support security teams in SIEM workflows (if correlated with ES).
* Performance Tuning & Optimization
* Optimize index configurations, search head performance, and data retention strategies.
* Perform load balancing and clustering health checks.
* Identify inefficient SPL queries and improve search performance.
* Automation & Dev Ops
* Automate deployment of apps, configurations, and forwarders using deployment server or CI/CD pipelines.
* Create scripted inputs, modular inputs, and REST-based integrations.
* Utilize tools such as Ansible, Puppet, or Terraform for Splunk environment automation.
* Documentation & Governance
* Document data onboarding, field extractions, dashboards, and operational procedures.
* Maintain runbooks, SOPs, and architectural diagrams.
* Work with governance teams to validate logging requirements and retention schedules.
* Collaboration & Customer Support
* Partner with application teams, network teams, and security analysts to deliver logging solutions.
* Consult internal stakeholders on best practices for dashboards, alerts, and log ingestion.
* Provide training for Splunk usage, SPL query writing, and dashboard development.
Key Responsibilities:
Splunk Administration
* Install, configure, and maintain Splunk Enterprise and Splunk Cloud environments.
* Manage Splunk Indexers, Search Heads, Forwarders, Deployment Servers, and Clusters.
* Develop and maintain dashboards, reports, alerts, and monitoring solutions.
* Configure log ingestion from servers, applications, network devices, and cloud platforms.
* Optimize Splunk performance, retention policies, and indexing strategies.
* Perform troubleshooting and root cause analysis of Splunk platform issues.
* Support security monitoring, threat detection, and compliance reporting requirements.
* Design and implement Splunk use cases for operational and security monitoring.
* Work with infrastructure and security teams to onboard new data sources. Microsoft 365 Administration
* Administer Microsoft 365 tenant, including Exchange Online, Teams, SharePoint Online, One Drive, and Microsoft Purview.
* Manage user provisioning, licensing, groups, and role assignments through Microsoft Entra (Azure AD).
* Configure and support Microsoft Teams policies, calling, meetings, and collaboration services.
* Administer Exchange Online mailboxes, mail flow, distribution groups, and hybrid configurations.
* Manage SharePoint Online sites, permissions, and document management solutions.
* Monitor service health and proactively address performance or availability issues.
* Support Microsoft Defender and security compliance initiatives.
* Implement data retention, DLP, eDiscovery, and governance…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×