SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Splunk Administrator

Securiti - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Veeam, the Data and AI Trust Company, is seeking a Senior Splunk Administrator to own and evolve the company's Splunk environment across on-premises and Splunk Cloud deployments. This role sits at the intersection of infrastructure, security, cloud, monitoring, and operational data—partnering with infrastructure, cloud, security, application, audit, and service management teams to deliver enterprise-scale observability. Key responsibilities include managing and maintaining Splunk Enterprise and Splunk Cloud environments; designing and supporting scalable log ingestion patterns across infrastructure, cloud platforms, applications, SaaS tools, security systems, and business services; monitoring and improving platform health, search performance, index utilization, storage efficiency, and data quality; building and maintaining dashboards, alerts, reports, saved searches, field extractions, and knowledge objects; leading data onboarding efforts including source validation, parsing, sourcetype strategy, and HEC integrations; troubleshooting complex issues across Splunk architecture, operating systems, networks, certificates, and data pipelines; supporting security, compliance, audit, and operational reporting use cases; and defining, documenting, and improving Splunk standards, runbooks, and platform best practices. You'll work with Splunk Enterprise and Cloud, Search Processing Language (SPL), Universal and Heavy Forwarders, Deployment Servers, Search Heads, Indexers, HTTP Event Collector (HEC), Splunk apps and add-ons, Windows and Linux environments, Azure services, REST APIs, PowerShell, Python, Bash, and IT service management tools like ServiceNow and Jira. Required qualifications include senior-level experience administering, engineering, or architecting Splunk in an enterprise environment; hands-on experience with Splunk Enterprise and/or Splunk Cloud; strong understanding of Splunk architecture including forwarders, indexers, search heads, apps, technical add-ons, indexes, sourcetypes, parsing, and retention; experience onboarding data from multiple source types; strong SPL skills for creating and optimizing searches, dashboards, reports, and alerts; experience improving data quality, field extraction, search efficiency, and platform stability; strong troubleshooting skills across infrastructure, networking, operating systems, and distributed systems; and experience using scripting or APIs to automate tasks. Bonus qualifications include Splunk certifications (Core Certified Power User, Advanced Power User, Enterprise Admin, Cloud Admin, Architect, or Consultant); security certifications; experience with Splunk Enterprise Security, Edge Processor, or search workload optimization; SOX, audit, compliance, or security operations experience; Azure Event Hub and cloud-to-cloud data ingestion experience; CIM and data models expertise; and familiarity with Veeam products or backup infrastructure monitoring.

Similar roles