Splunk Architect - Enterprise Security
Pune, Maharashtra, India · Full Time
Be the first to apply
- Experience
- 8+ yrs
- Salary
- INR 4,000,000 – INR 6,000,000 / year
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Education
- Any graduate
- Eligibility
- Open to all graduates.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are looking for a seasoned and certified Splunk Architect to lead the design, deployment, and management of a complex, distributed Splunk Enterprise and Enterprise Security (ES) environment. This key technical leadership position involves developing a long-term architectural vision for the Splunk platform to ensure optimal scalability, availability, and security aligned with enterprise cybersecurity goals.
Key Responsibilities
- Lead architectural design and strategy for Splunk Enterprise and Splunk ES in distributed, high-availability, and cloud or hybrid infrastructures.
- Design, implement, and maintain indexer and search head clusters, deployment servers, and forwarders with performance and resilience optimization.
- Conduct capacity planning and performance tuning across all Splunk components.
- Architect security-centric dashboards, data models, and advanced analytics to enhance threat detection, incident response, and forensic processes.
- Implement and configure Splunk Enterprise Security features including correlation searches, notable event creation, risk scoring, and integration with threat intelligence frameworks.
- Oversee onboarding and normalization of a variety of data sources (including OS, network, application, and cloud logs) adhering strictly to Splunk CIM standards.
- Establish and maintain configuration management, security hardening, and change control procedures for Splunk environments.
- Develop complex Splunk SPL queries, reports, and visualizations for diverse security scenarios.
- Integrate Splunk with external security systems and tools such as SOAR, CMDB, and other SIEMs through APIs and custom development.
- Provide guidance and mentorship to Splunk administrators, engineers, and security analysts on SPL, CIM, ES features, and best practices.
- Create and update thorough documentation including conceptual architectures, reference models, and operational runbooks.
- Work closely with cybersecurity leadership and key stakeholders to align Splunk platform roadmap with organizational security and business strategies.
Qualifications and Experience
- At least 8 years of overall experience in IT, with a minimum of 5 years specializing in Splunk Enterprise and Enterprise Security architecture and engineering within large-scale enterprise environments.
- Expert knowledge of Splunk deployment architectures, including multi-site clustering, SmartStore technology, and high-availability setup.
- Skilled in developing security use cases, threat modeling, and building efficient correlation searches in Splunk ES.
- Proficient in scripting languages (Python, Bash, or PowerShell) to automate installation and maintenance workflows.
- Strong technical background in core security principles, networking protocols, Linux/Windows OS, and cloud platforms such as AWS, Azure, or Google Cloud.
- Must hold current certifications: Splunk Enterprise Certified Architect and Splunk Enterprise Security Certified Admin; Splunk Core Certified Consultant highly preferred.
Preferred Skills and Certifications
- Experience with Splunk SOAR or IT Service Intelligence (ITSI) platforms.
- Additional industry certifications like CISSP, CISM, or CompTIA Security+.
- Experience using Infrastructure as Code tools such as Ansible or Terraform for managing Splunk deployments.
Eligibility and Education
The position requires any graduate to apply.
Minimum education
Bachelor's Degree