Splunk Engineer

Full time on site
Splunk Engineer
Job Description

The Splunk Engineer designs, maintains, and optimizes enterprise Splunk infrastructures. They manage data ingestion pipelines, build custom dashboards, write Splunk Processing Language (SPL) queries, and support IT operations, security monitoring, or SIEM environments.

Key Responsibilities

  • Infrastructure Management: Deploy, configure, and maintain Splunk Enterprise or Splunk Cloud components, including indexers, forwarders, and search heads.
  • Data Onboarding: Inboard new data sources from cloud platforms, servers, and network devices, ensuring correct parsing and data normalization.
  • Query and Dashboard Development: Create advanced SPL queries, reports, and custom dashboards for monitoring operational metrics and security alerts.
  • System Optimization: Tune performance, manage index retention policies, and troubleshoot ingestion or clustering bottlenecks.
  • Cross-Functional Collaboration: Partner with security (SOC), infrastructure, and DevOps teams to align logging, monitoring, and compliance needs.

Required Qualifications and Skills

  • Technical Experience: 5+ years managing clustered Splunk production environments.
  • SPL Proficiency: Strong command of Splunk Processing Language (SPL) for searches, macros, and regex.
  • Scripting \& Automation: Familiarity with Python, Bash, or PowerShell, alongside infrastructure-as-code tools like Terraform.
  • System Administration: Solid background in Linux/Unix and Windows server administration plus general networking principles.

Certifications: Preferred credentials include Splunk Certified Administrator or Splunk Enterprise Certified Architect.

Pay: RM8,000.00 - RM14,000.00 per month

Benefits:

  • Health insurance
  • Maternity leave
  • Opportunities for promotion
  • Professional development

Work Location: In person

Share this job:
ES Assistant Online
Hello! I am your AI career assistant. How can I help you today?