Splunk ITSI Engineer
Core
Design advanced ITSI visualizations, build custom Glass Tables and Service Trees, and maintain data ingestion pipelines for enterprise monitoring intelligence.
Role type
Senior Splunk ITSI Engineer
Builds
Enterprise monitoring platform integrating Splunk with ServiceNow and external systems for the Defense Health Agency
Domain
Government IT / Cybersecurity / IT Operations
Required skills
Splunk ITSI (service/KPI modeling, glass tables, service trees), Splunk data ingestion (inputs, indexes, forwarders, pipelines), Linux administration, Python or PowerShell scripting, network protocols, security concepts, RMF compliance
Preferred skills
Splunk Computing Environment certifications (Enterprise, ITSI, ES, Architect), Military Health or federal health IT environment experience, ServiceNow ITSM (MHSSHD), integrating Splunk with external monitoring platforms, data analysis and statistical methods
Technologies
Splunk, ServiceNow, Linux, Python, PowerShell
Responsibilities
Design advanced ITSI visualizations and integrate contextual data into notable events; Build and maintain custom ITSI Glass Tables and Service Trees; Onboard new data sources into Splunk; Maintain data ingestion pipelines across application, system, and network logs; Configure Splunk data inputs, indexes, and processing pipelines; Monitor Splunk system health and tune configurations; Manage Splunk capacity planning; Use Splunk Enterprise Security to detect incidents and develop custom detection rules; Build advanced searches and reporting for anomaly detection; Support RMF compliance; Provide technical training and documentation.
Seniority
Senior, hands-on IC