Jobs · Engineering · New York

Senior Splunk Data Platform Architect – Azure & Kubernetes

Santcore Technologies · New York, NY · 4 wk ago
On-siteEngineering$90/hrFull-time

About the role

We are seeking an experienced Cyber Data Platform Architect to design, implement, and scale enterprise cyber data platforms supporting security operations, SIEM, observability, and incident response.

Responsibilities

  • Design, implement, and optimize enterprise Splunk architectures and data-ingestion pipelines.
  • Architect scalable platforms supporting cybersecurity, SIEM, observability, and operational analytics.
  • Integrate Kubernetes, Azure, cloud, infrastructure, application, network, and security data sources.
  • Configure and manage Splunk HEC, Universal Forwarders, Heavy Forwarders, Search Heads, Indexers, and deployment components.
  • Design reliable Syslog and log-routing solutions for large-scale environments.
  • Build highly available and scalable cloud-native data platforms on Microsoft Azure.
  • Automate infrastructure provisioning and configuration using Terraform, Ansible, and DevOps practices.
  • Develop automation and integration solutions using Python, Go, or Java.
  • Troubleshoot distributed systems, ingestion failures, search-performance issues, and platform bottlenecks.
  • Support capacity planning, performance tuning, platform upgrades, incident response, and operational reliability.
  • Implement monitoring, alerting, security controls, and platform-governance standards.
  • Partner with cybersecurity, infrastructure, cloud, DevOps, and application teams.

Requirements

  • Strong hands-on experience with Splunk Enterprise architecture and administration.
  • Experience designing and optimizing large-scale data-ingestion pipelines.
  • Hands-on experience with Splunk HEC, Universal Forwarders, Heavy Forwarders, Syslog, Search Heads, and Indexers.
  • Experience with Search Head Clustering and Indexer Clustering.
  • Strong knowledge of Kubernetes and cloud-native architectures.
  • Hands-on Microsoft Azure experience.
  • Experience with Terraform, Ansible, Infrastructure as Code, and CI/CD pipelines.
  • Programming or automation experience using Python, Go, or Java.
  • Strong Linux administration, networking, API-integration, and troubleshooting skills.
  • Experience supporting large-scale distributed systems and high-volume data platforms.
  • Strong understanding of platform scalability, availability, performance, and resiliency.

Qualifications

  • Experience with Kafka, ELK, Cribl, or similar data-routing and streaming platforms (preferred).
  • Experience with Splunk Enterprise Security, SIEM, EDR, SOAR, or cyber-observability platforms (preferred).
  • Experience integrating security, application, network, infrastructure, and cloud telemetry (preferred).
  • Familiarity with AI/ML-powered security analytics and automation (preferred).
  • Experience working within enterprise financial services, cybersecurity, or regulated environments (preferred).
  • Splunk, Azure, Kubernetes, Terraform, or Cribl certifications (preferred).

Similar jobs