What You'll Do:
Architecture & Design Design and implement distributed, high-performance Splunk Enterprise and ES architectures spanning on-premises and hybrid cloud environments. Define indexer clustering, search head clustering, and forwarder topologies to meet mission-scale ingestion and availability requirements.
Engineering & Optimization Build and optimize data ingestion pipelines, develop data models, and tune search performance for reliability and scalability. Develop custom TAs and field extractions for diverse federal log sources including endpoints, network devices, cloud platforms, and security tools.
Security & Compliance Ensure platform compliance with FISMA, NIST RMF, M-21-31 log retention mandates, CDM program requirements, and FedRAMP authorization boundaries.
Strategy & Leadership Provide technical governance over Splunk platform decisions and roadmap evolution. Mentor junior engineers on SPL, data onboarding, and ES content development. Collaborate with SOC, network, and IT teams to align Splunk capabilities with operational and mission objectives.
The ideal candidate possesses strong analytical and troubleshooting skills, with the ability to diagnose complex technical issues and rapidly develop practical, effective solutions. This role requires someone who can clearly articulate findings and recommended actions to leadership to support informed decision‑making. The candidate must also be adept at working within a structured change‑management framework and ensuring full compliance with applicable government oversight and governance requirements.
The candidate must be able to engage effectively with non‑technical stakeholders, guiding them through complex processes and operational steps in a clear, patient, and structured manner. This includes translating technical concepts into accessible language, ensuring stakeholders understand required actions, and providing steady support to help them successfully complete tasks.
What You've Done:
- US Citizenship is Required
- Ability to pass a DHS EOD Clearance
- Bachelor's degree plus 10 years of relevant experience, or Master's degree plus 15 years.
- 10+ years of Splunk experience in a large clustered environment.
- Demonstrated expertise in Splunk administration and architecture, Linux administration, cloud platforms (AWS/Azure), scripting, and log parsing.
- Splunk Architect certifications required; Splunk ES Certified Admin
- Cribl Admin certification preferred.
- Public Trust eligibility required
- [Secret clearance preferred]
What We Offer:
- 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
- Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
- Group Term Life, Short-Term Disability, Long-Term Disability
- Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
- Participation in the Discretionary Time Off (DTO) Program
- 11 Paid Holidays Annually
Top Skills
Similar Jobs
What you need to know about the Charlotte Tech Scene
Key Facts About Charlotte Tech
- Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
- Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
- Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
- Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus


