- Company Name
- Brooksource
- Job Title
- Security Architect
- Job Description
-
**Job Title:** Security Architect – Splunk
**Role Summary:**
Design, build, and optimize enterprise‑level Splunk solutions that deliver monitoring, security, compliance, and operational visibility across cloud and on‑premise environments. Lead technical direction, mentor junior staff, and ensure high‑performance, scalable, and secure Splunk infrastructure.
**Expactations:**
- Deliver end‑to‑end Splunk architectures aligned with business and security goals.
- Ensure reliability, scalability, and security of logging and analytics platforms.
- Drive automation, best‑practice adoption, and continuous improvement.
- Provide technical leadership and knowledge transfer to team members.
**Key Responsibilities:**
- Architect and deploy Splunk components (indexers, search heads, deployment servers, forwarders, clusters).
- Create and maintain dashboards, data models, reports, and alerts.
- Ingest and normalize data from logs, metrics, AWS/Azure/GCP, and third‑party APIs.
- Define and enforce performance, scalability, and security standards for Splunk.
- Mentor junior Splunk engineers and analysts.
- Collaborate with Security, DevOps, Infrastructure, and Application teams for observability and incident response.
- Automate data ingestion, parsing, and enrichment (Python, Bash, Ansible, PowerShell).
- Troubleshoot performance issues and apply tuning recommendations.
- Document architecture, configurations, and SOPs.
- Stay updated on Splunk releases, industry trends, and emerging technologies.
**Required Skills:**
- 5+ years designing and managing large‑scale Splunk environments (Enterprise, Cloud, ES).
- Deep expertise in SPL, data onboarding, sourcetypes, props/transforms, and CIM.
- Experience with distributed Splunk architectures, clustering, and HA.
- Proficient in scripting/automation (Python, Bash, Ansible, PowerShell).
- Strong knowledge of security frameworks (NIST, ISO 27001) and compliance (HIPAA, PCI‑DSS).
- Hands‑on Linux/Unix command‑line skills.
- Ability to work cross‑functionally and mentor staff.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Preferred: Splunk Certified Architect and/or Splunk Certified Admin.
- Additional preferred: Experience with Splunk ITSI, SOAR (Phantom), custom apps, cloud‑native logging (CloudWatch, Stackdriver), and Kubernetes observability.