Splunk Data Administrator
Core
Own and continuously improve Splunk data onboarding, normalization, and quality across a complex hybrid Splunk environment (on-prem and cloud) to ensure logs are usable for security/IT operations, dashboards, and correlation searches.
Role type
Senior Splunk Data Administrator (CIM & Data Onboarding)
Builds
Normalized, high-fidelity log data pipelines for security monitoring, incident response, and operational reporting.
Domain
Security Information and Event Management (SIEM) / Log Management / Hybrid Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Splunk administration, CIM normalization, field extraction (regex/JSON/KV), props.conf/transforms.conf configuration, TA deployment, hybrid architecture operations, pipeline troubleshooting, SPL scripting, log source knowledge (Security/Infrastructure/Cloud)
Preferred skills
Splunk Enterprise Security (ES) experience, Splunk Ingest Actions/Edge Processor, HEC/API ingestion, ITSI/Observability, Splunk certifications
Technologies
Splunk Enterprise, Splunk Cloud, CIM, Heavy Forwarders, Universal Forwarders, Indexer Clusters, Search Head Clusters, Deployment Server, Syslog, HEC, AWS/Azure/GCP
Responsibilities
Lead end-to-end onboarding of new log sources including requirements gathering, parsing strategy, and release; Normalize data to Splunk Common Information Model (CIM) to support Enterprise Security; Design and implement robust field extractions and enrichment using props.conf, transforms.conf, and ingest actions; Install, configure, and maintain Splunk Add-ons (TAs) across forwarders, indexers, and search heads; Operate and support complex hybrid Splunk architectures (on-prem + cloud) and troubleshoot ingestion pipelines; Monitor ingestion health, pipeline performance, and enforce data governance standards.
Seniority
Mid–Senior, hands-on IC