Senior Splunk Architect; Hybrid
Listed on 2025-12-20
-
IT/Tech
Cybersecurity, Data Security
Title: Senior Splunk Architect (Hybrid)
State Role
Title:
Salary Non-Specified
Hiring Range: ,0000
Pay Band: UG
Agency: Virginia Retirement System
Location: Virginia Retirement System
Agency Website: (Use the "Apply for this Job" box below)./careers
Recruitment Type: General Public - G
Job DutiesThe Senior Splunk Architect is responsible for assisting with designing, implementing, and optimizing VRS’ Splunk environment to support enterprise-scale data ingestion, security monitoring, IT operations, and analytics. This role helps drives high performance, scalability, and compliance with organizational security standards. The role also requires collaboration with cross-functional teams to deliver actionable insights from log data and enhance the organization’s insights and security posture.
Architecture& Design
- Assist in designing and implementing scalable, resilient Splunk Enterprise and Splunk Cloud architectures (including indexers, search heads, forwarders, and deployment servers).
- Help to define and contribute to best practices for data onboarding, parsing, and normalization.
- Support the design of multi-site, distributed Splunk environments for performance and disaster recovery.
- Deploy and configure Splunk Enterprise Security (ES) or Splunk Cloud components, including indexers, search heads, forwarders, and deployment servers.
- Deploy and configure Splunk components (Enterprise, Universal Forwarders, Heavy Forwarders).
- Maintain and optimize Splunk environments for scalability, high availability, and performance.
- Assist in managing data ingestion pipelines from diverse data sources (syslog, APIs, cloud logs, databases, etc.).
- Implement and maintain index configurations, props/transforms, and data parsing logic.
- Integrate Splunk with other enterprise systems.
- Develop and maintain custom apps, dashboards, and alerts tailored to business needs.
- Help oversee data ingestion from multiple sources, including syslog, APIs, and cloud services.
- Optimize indexing, search performance, and storage strategies to ensure cost‑effective operations.
- Implement data retention, archival, and lifecycle management policies.
- Assist in designing and developing advanced dashboards, reports, and alerts using SPL (Search Processing Language).
- Tune search performance, optimize indexing strategies, and manage data lifecycle policies.
- Support the development and enforcement of Splunk governance, user roles, and access control frameworks.
- Ensure data security and compliance with enterprise and regulatory standards (e.g., NIST 800‑53, SEC
530). - Demonstrate technical expertise in incident response and forensic investigations using Splunk.
- Collaborate with Dev Ops and IT operations teams to maximize Splunk value across the enterprise.
- Stay current on new Splunk features, add‑ons, and industry trends to guide strategic improvements.
- Eight (8) years of experience in SIEM architecture, engineering, or administration.
- Experience designing and managing large, distributed Splunk environments.
- Hands‑on experience with Splunk Enterprise Security (ES).
- Strong knowledge of Linux/Unix systems, networking, and data security concepts. Proficiency with scripting and automation. Familiarity with cloud infrastructure (AWS, Azure, or GCP) and hybrid Splunk deployments.
Bachelor’s degree in computer science, or related field preferred.
Experience in SIEM engineering, SOC operations, or cybersecurity analytics, Scripting AI, SASE, or Cloud Security. Comprehensive knowledge in multiple disciplines and areas within information technology. Ability to apply and support enforcement of information security principles and policies. Understanding of network protocols, operating systems, firewalls, anti‑malware software and intrusion detection systems is preferred.
Excellent verbal and written communication skills. Ability to prioritize own work activities with minimal guidance and complete complex projects independently with minimal oversight and direction. Ability to manage competing priorities to meet goals. Ability to motivate others to implement security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).