Splunk Architect – Enterprise Security Specialist
Primary Purpose and Goal of Role
We are seeking a highly experienced Splunk Architect with 5-10 years of Splunk Cloud expertise, including hands-on knowledge of Enterprise Security (ES), SOAR, data ingestion, and dashboard development. This role demands proficiency in federal compliance frameworks (M-2131, NIST, CMMC) and gap assessments, providing customer recommendations and strategic roadmaps. The successful candidate will design and implement cutting-edge security solutions to enhance data visibility and automate threat detection for both enterprise and government environments.
Responsibilities
1. Splunk Cloud Architecture & Deployment:
- Lead the design, deployment, and management of Splunk Cloud environments, ensuring performance, scalability, and reliability.
- Migrate on-premise Splunk deployments to Splunk Cloud, ensuring seamless data flow, minimal disruption, and security compliance.
- Manage and optimize Splunk Cloud services, ensuring integration with enterprise data sources and hybrid environments.
- Stay current with Splunk Cloud innovations to enhance functionality and performance through regular updates and best practices.
2. Enterprise Security (ES) & SOAR:
- Architect and deploy Splunk Enterprise Security (ES) to support real-time threat monitoring, advanced correlation, and incident response.
- Develop and optimize SOAR playbooks to automate workflows and incident responses, reducing manual effort for SOC teams.
- Ensure that security analytics align with Zero Trust architecture and other government mandates.
3. Data Ingestion & Dashboard Development:
- Design robust data ingestion pipelines for cloud and hybrid environments, integrating data from multiple sources (Syslog, APIs, databases, SaaS platforms).
- Develop custom dashboards, visualizations, and reports to meet enterprise and government compliance requirements.
- Maintain data models to support high-performance searches and analytics, ensuring scalability across large datasets.
4. Gap Assessment & Customer Recommendations:
- Perform comprehensive gap assessments of existing Splunk implementations, identifying weaknesses, and opportunities for improvement.
- Provide strategic recommendations, roadmaps, and timelines to enhance security posture and optimize Splunk Cloud performance.
- Work closely with customers to remediate gaps, ensuring alignment with NIST 800-53, CMMC, M-2131, and other frameworks.
5. Federal Security & M-2131 Compliance:
- Ensure all Splunk deployments meet OMB M-2131 directives and align with federal security requirements, including NIST 800-53 and CMMC Level 2/3.
- Collaborate with government security teams to implement Zero Trust principles within Splunk Cloud environments.
- Support incident response workflows to align with FedRAMP, FIPS, and other federal data protection policies.
6. Collaboration & Leadership:
- Lead cross-functional teams, including SOC analysts, engineers, and compliance specialists, to implement security solutions.
- Provide mentoring and guidance to junior team members and Splunk developers to build internal expertise.
- Collaborate with product managers, customers, and compliance experts to align solutions with business needs and security frameworks.
REQUIREMENTS
Required Skills & Experience:
- 5-10 years of Splunk Cloud experience, including architecture, deployment, and optimization.
- Proven success in migrating on-premise environments to Splunk Cloud and maintaining hybrid deployments.
- Expertise with Splunk Enterprise Security (ES) and SOAR for security monitoring, orchestration, and automation.
- Deep knowledge of data ingestion frameworks, including cloud-based data sources (AWS, Azure, SaaS) and log management.
- Strong experience building dashboards, alerts, and visualizations tailored to enterprise and federal requirements.
- Hands-on experience with gap assessments, roadmaps, and customer recommendations.
- Familiarity with federal frameworks, including OMB M-2131, NIST 800-53, CMMC, Zero Trust, and FedRAMP.
- Proficiency with incident response workflows and automation using SOAR playbooks.
- Strong understanding of Linux, networking, and cloud services (AWS, Azure, or others).
Preferred Qualifications:
- Splunk Certified Architect or Enterprise Security Certified Admin.
- Experience working with MDR tools and services for federal agencies.
- Familiarity with the MITRE ATT&CK framework and threat intelligence platforms.
- Practical knowledge of SIEM integrations and compliance tools like Cybertorch™ or equivalent.
- Knowledge of federal acquisition regulations (FAR) and related compliance.
- Certification in proposal management (e.g., APMP).
Soft Skills:
- Strong analytical and problem-solving skills with a focus on performance optimization.
- Excellent communication and interpersonal skills, with the ability to engage both technical and non-technical stakeholders.
- Demonstrated leadership skills and the ability to drive complex projects from initiation to completion.
- Ability to work independently and collaboratively in a fast-paced environment.