Search by job, company or skills

Unison Group

Splunk Engineer

Early Applicant
  • Posted 12 days ago
  • Be among the first 10 applicants
3-5 Years

Job Description

The proposed Splunk Engineer shall have the following qualifications:

  • At least 3 years experience working on Splunk system
  • Possess Splunk Enterprise Certified Admin certifications or equivalent.

Working arrangement:

  • To able to work independently and ensure smooth running of the System. Official working hours: 8.30am to 6.00pm (Monday to Thursday), 8.30 to 530pm (Friday) and based on-site.

The Splunk Engineer shall perform critical high-risk works during maintenance windows specified by the Client, which may be off-office hours or during weekends.

The Splunk Engineer shall be responsible of all the corrective and preventive maintenance of the Splunk systems in all environments.

The Splunk Engineer shall remediate all vulnerabilities or penetration test findings pertaining to the Splunk systems.

The Splunk Engineer can raise tickets to Splunk principal for support and queries.

System Operations

  • Perform checks and troubleshoot, if necessary, to ensure the Client's Splunk services are running as intended for all environments
  • Maintain and monitor Splunk infrastructure (Search Heads, Indexers, Forwarders, Deployment Server, Cluster Master, etc.)
  • Ensure uptime and system health via monitoring, tuning, and log analysis (including introspection, metrics logs)
  • Manage indexing performance and storage usage: data retention, index lifecycle, bucket management
  • Generate and check reports from the system to ensure the system and agents are working as intended
  • Perform checks and troubleshoot, if necessary, to ensure that the Splunk forwarders (agents) are working and can pipe logs back to Splunk systems
  • Perform checks and troubleshoot, if necessary, to ensure the Splunk systems can receive logs from sources such as CloudWatch or syslog servers
  • Integrate Splunk with the Client's systems and processes to perform real-time monitoring and alert when Splunk infrastructure is not working well, so that issues can be attended to early. (e.g., log breaks, disconnected agents, search-head hung from insufficient resources, etc.)
  • Fine tune Splunk rules according to the Client's request
  • Perform parser validation or write new custom parser according to the Client's request
  • Work closely with the Client's SOC to ensure Splunk supports threat detection, auditing, and incident response use cases
  • Change the passwords for all privilege and services accounts for the Splunk systems regularly
  • Ensure the Splunk systems is working as intended during the Client's periodic BCP and DR exercises

Problem Resolution

  • Investigate problems and provide assistance to triage issues
  • Correct defects in the System, including temporary corrections or workarounds until permanent fixes or updates are available
  • Prepare incident report including the root cause analysis and necessary resolution
  • Track and report issues, support cases and incident resolutions on a weekly basis

System Monitoring

  • Monitor Security advisory, new releases, notifications and maintenance expiry dates for all Software used in the System and assess the impact, if any
  • Recommend to the Client the best course of action to take and provide all relevant documentation
  • If the issue arises from a security vulnerability or software incompatibility, the RE shall evaluate and implement fixes to address the vulnerability or incompatibility
  • Check and remediate findings from the Client's periodic vulnerability and compliance scans
  • Track and update the Client on the DLP End of Life (EOL) and End of Support (EOS) and plans to maintain product supportability

System Changes

  • Deploy and test system changes in the non-Production environments when required
  • Demonstrate that System functionality and performance are not degraded
  • Implement the system changes into the Production environment upon the Client's acceptance of the testing results
  • Implementation of additional use cases, report design and development and tuning to reduce false positives and negatives

Documentation

  • Create or provide the Client with all System related documentation, including standards and procedures, operation manuals, workflows, processes, etc
  • Update the relevant documentation when changes are made to the System or processes

More Info

Industry:Other

Function:Information Technology

Job Type:Permanent Job

Date Posted: 19/09/2025

Job ID: 126605339

Report Job

About Company

View More
Last Updated: 01-10-2025 02:21:49 AM

Similar Jobs