Splunk Architect
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer, Security Management & Operations
Certified Splunk Architect Overview
We're looking for an intelligent, imaginative, highly skilled and driven Certified Splunk Architect to work alongside some of the best in the industry in a team focused setting. We are creating with the Splunk environment never before seen Security, Operations and Business use cases. You will design, implement, and maintain a complex, large-scale Splunk environment. This role requires deep expertise across the entire Splunk Enterprise and Cloud platforms (Hybrid).
The successful candidate will have Splunk Enterprise Security, specifically detection engineering expertise.
- Detection Engineering:
Build and update custom detection rules, leverage and integrate detections with 3rd party tools (including Splunk Behavioral Analytics), all within a Risk Based Alerting format. - Solution Development:
Architect and implement specialized Splunk solutions, particularly Splunk Enterprise Security (ES), to deliver actionable insights and use cases. - Automation:
Design and build workflows for pre and post ticket automation, using Splunk SOAR and other tools. - Reporting:
Create the next level of security detection readiness executive and engineer dashboard(s). - Performance Optimization:
Conduct regular health checks and performance tuning of the Splunk environment, optimizing search latency, data processing, and resource utilization across the infrastructure. - Technical Leadership:
Serve as a subject matter expert (SME) for all Splunk technologies, providing technical leadership, documentation, and mentorship to Security, Operations and Business teams.
- Certification:
Must possess current, active certification as a Splunk Certified Architect (preferred: Splunk Certified Core Consultant). - Experience:
3+ years of progressive experience working with the Splunk platform; at least 1 year dedicated detection engineering. - Scripting & Automation:
Proficient in scripting languages (Python, Bash) for deployment automation, configuration management, and API integration. - Cloud Proficiency:
Hands-on experience deploying and managing Splunk in AWS, Azure, or GCP environments, including understanding of relevant cloud services/sources of security data. - Technical Depth:
Splunk Deployment Servers, Splunk Data Collection Nodes, Splunk intermediary forwarders, Splunk DB Connect, Splunk Universal Forwarders (Linux, Solaris, Windows, Mac), rsyslog collectors, data processing pipeline (preferred ingest/edge processor);
Splunk SOAR. - Communication:
Excellent written and verbal communication skills, with the ability to articulate complex technical concepts to both business and technical audiences.
Health, Dental, Vision Insurance Matching 401K REMOTE role - You MUST be located in Costa Rica Long Term Contract Paying up to $30/hr #IND1
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).