Jobs and Careers
EC

Senior Splunk Engineer

ECS
Work from home, VA, United States, United StatesRemotefull_timeVerifiedPosted 11 Jun 2026

About the role

Everforth ECS is seeking a Senior Splunk Engineer to work in our Portland, OR office or Remotely

 

The Senior Splunk Engineer designs, implements, maintains, and optimizes Splunk capabilities that support cybersecurity monitoring, investigation, reporting, and security operations. This role is responsible for Splunk platform engineering, data onboarding, search performance, dashboards, alerts, integrations, and technical support for SOC and cybersecurity stakeholders. 

The ideal candidate has deep hands-on experience administering Splunk Enterprise, Splunk Enterprise Security, or Splunk Cloud environments; understands security data pipelines and SIEM operations; and can independently troubleshoot complex platform, data ingestion, parsing, indexing, search, and content issues while collaborating with analysts, engineers, and program leadership. 

 

Key Responsibilities 

Splunk Platform Engineering & Administration 

  • Administer, configure, maintain, and optimize Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or distributed Splunk environments. 
  • Support indexers, search heads, deployment servers, heavy forwarders, universal forwarders, apps, add-ons, knowledge objects, and role-based access controls. 
  • Monitor platform health, availability, license utilization, data ingestion, storage, capacity, search concurrency, and overall performance. 
  • Plan and execute upgrades, patches, configuration changes, backup and recovery activities, and platform maintenance in accordance with change management processes. 

Data Onboarding & Integration 

  • Onboard, normalize, validate, and maintain security, infrastructure, cloud, endpoint, network, application, identity, and operational data sources. 
  • Configure and troubleshoot inputs, forwarders, sourcetypes, indexes, props.conftransforms.conf, field extractions, lookups, event types, tags, and data routing. 
  • Map data to the Splunk Common Information Model and support data model acceleration, normalization, and content readiness for security analytics. 
  • Integrate Splunk with security tools, ticketing systems, SOAR platforms, vulnerability tools, EDR solutions, firewalls, IDS/IPS, cloud platforms, and identity systems. 

Security Analytics & Detection Support 

  • Develop, maintain, and tune SPL searches, correlation searches, alerts, dashboards, reports, notable event rules, and security monitoring use cases. 
  • Partner with SOC analysts, threat hunters, threat intelligence analysts, and security engineers to translate detection requirements into reliable Splunk content. 
  • Tune detections and searches to improve fidelity, reduce false positives, increase operational value, and support risk-based alerting or prioritization. 
  • Support incident response and investigations by validating log availability, developing ad hoc searches, retrieving evidence, and assisting with event timelines. 

Dashboarding, Reporting & Metrics 

  • Design and maintain dashboards, reports, scorecards, and visualizations for SOC operations, platform health, data coverage, compliance, and leadership reporting. 
  • Track and report key Splunk metrics such as ingestion volume, license consumption, search performance, alert volume, source coverage, and data quality.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ECS

View company profile →