Skip to content
bg-office-working-unsplash

Splunk Architect – Enterprise Security Specialist

Full-time
United States - Must Work East Coast Hours
100% Remote

Primary Purpose and Goal of Role  

We are seeking a highly experienced Splunk Architect with 5-10 years of Splunk Cloud expertise, including hands-on knowledge of Enterprise Security (ES), SOAR, data ingestion, and dashboard development. This role demands proficiency in federal compliance frameworks (M-2131, NIST, CMMC) and gap assessments, providing customer recommendations and strategic roadmaps. The successful candidate will design and implement cutting-edge security solutions to enhance data visibility and automate threat detection for both enterprise and government environments.

Responsibilities

1. Splunk Cloud Architecture & Deployment:

      • Lead the design, deployment, and management of Splunk Cloud environments, ensuring performance, scalability, and reliability.
      • Migrate on-premise Splunk deployments to Splunk Cloud, ensuring seamless data flow, minimal disruption, and security compliance.
      • Manage and optimize Splunk Cloud services, ensuring integration with enterprise data sources and hybrid environments.
      • Stay current with Splunk Cloud innovations to enhance functionality and performance through regular updates and best practices.

2. Enterprise Security (ES) & SOAR:

      • Architect and deploy Splunk Enterprise Security (ES) to support real-time threat monitoring, advanced correlation, and incident response.
      • Develop and optimize SOAR playbooks to automate workflows and incident responses, reducing manual effort for SOC teams.
      • Ensure that security analytics align with Zero Trust architecture and other government mandates.

3. Data Ingestion & Dashboard Development:

    • Design robust data ingestion pipelines for cloud and hybrid environments, integrating data from multiple sources (Syslog, APIs, databases, SaaS platforms).
    • Develop custom dashboards, visualizations, and reports to meet enterprise and government compliance requirements.
    • Maintain data models to support high-performance searches and analytics, ensuring scalability across large datasets.

4. Gap Assessment & Customer Recommendations:

      • Perform comprehensive gap assessments of existing Splunk implementations, identifying weaknesses, and opportunities for improvement.
      • Provide strategic recommendations, roadmaps, and timelines to enhance security posture and optimize Splunk Cloud performance.
      • Work closely with customers to remediate gaps, ensuring alignment with NIST 800-53, CMMC, M-2131, and other frameworks.

5. Federal Security & M-2131 Compliance:

      • Ensure all Splunk deployments meet OMB M-2131 directives and align with federal security requirements, including NIST 800-53 and CMMC Level 2/3.
      • Collaborate with government security teams to implement Zero Trust principles within Splunk Cloud environments.
      • Support incident response workflows to align with FedRAMP, FIPS, and other federal data protection policies.

6. Collaboration & Leadership:

    • Lead cross-functional teams, including SOC analysts, engineers, and compliance specialists, to implement security solutions.
    • Provide mentoring and guidance to junior team members and Splunk developers to build internal expertise.
    • Collaborate with product managers, customers, and compliance experts to align solutions with business needs and security frameworks.
bg-office-unsplash-02
bg-office-unsplash-01
bg-office-group-of-people-talking-498623425

REQUIREMENTS

Required Skills & Experience:

    • 5-10 years of Splunk Cloud experience, including architecture, deployment, and optimization.
    • Proven success in migrating on-premise environments to Splunk Cloud and maintaining hybrid deployments.
    • Expertise with Splunk Enterprise Security (ES) and SOAR for security monitoring, orchestration, and automation.
    • Deep knowledge of data ingestion frameworks, including cloud-based data sources (AWS, Azure, SaaS) and log management.
    • Strong experience building dashboards, alerts, and visualizations tailored to enterprise and federal requirements.
    • Hands-on experience with gap assessments, roadmaps, and customer recommendations.
    • Familiarity with federal frameworks, including OMB M-2131, NIST 800-53, CMMC, Zero Trust, and FedRAMP.
    • Proficiency with incident response workflows and automation using SOAR playbooks.
    • Strong understanding of Linux, networking, and cloud services (AWS, Azure, or others).

Preferred Qualifications:

      • Splunk Certified Architect or Enterprise Security Certified Admin.
      • Experience working with MDR tools and services for federal agencies.
      • Familiarity with the MITRE ATT&CK framework and threat intelligence platforms.
      • Practical knowledge of SIEM integrations and compliance tools like Cybertorch™ or equivalent.
      • Knowledge of federal acquisition regulations (FAR) and related compliance.
      • Certification in proposal management (e.g., APMP).

Soft Skills:

    • Strong analytical and problem-solving skills with a focus on performance optimization.
    • Excellent communication and interpersonal skills, with the ability to engage both technical and non-technical stakeholders.
    • Demonstrated leadership skills and the ability to drive complex projects from initiation to completion.
    • Ability to work independently and collaboratively in a fast-paced environment.
Quzara LLC is an Equal Employment/Affirmative Action employer. We do not discriminate in hiring based on sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state, or local law. 

Join Our Cyber Team!

Working for Quzara means being part of a team driven by innovation and dedication where we rise together.