Jobs · Engineering · Tennessee

Splunk Onboarding Content Engineer

First Horizon Bank · Memphis, TN · 3 days ago
EngineeringFull-time

About the role

The Splunk Onboarding and Content Engineer serves as the primary coordinator for application log onboarding into Splunk, working closely with application owners, developers, infrastructure teams, security teams, risk partners, and vendors.

Responsibilities

  • Serve as the primary coordinator for application log onboarding into Splunk, managing intake, discovery, requirements, dependencies, testing, production readiness, and handoff.
  • Partner with application owners, developers, infrastructure teams, security teams, risk partners, and vendors to identify available log sources, transport methods, environments, owners, retention needs, and priority use cases.
  • Assess proposed log sources for security, audit, compliance, fraud, troubleshooting, and operational value; help teams distinguish required telemetry from low-value or duplicative data.
  • Gather and document host names, file paths, APIs, database connections, cloud services, event streams, authentication requirements, network dependencies, service accounts, and sample events needed for onboarding.
  • Cook up onboarding across common collection methods, including universal forwarders, syslog, APIs, database connectors, cloud integrations, event hubs, and supported Splunk add-ons.
  • Validate data flow, timestamp accuracy, source and sourcetype assignment, field extraction, event breaking, permissions, completeness, and search performance.
  • Normalize and enrich data using the Splunk Common Information Model, field aliases, calculated fields, tags, event types, lookups, and supporting reference data.
  • Create and maintain dashboards, alerts, correlation searches, reports, scheduled searches, drilldowns, and reusable search content aligned with application-owner needs.
  • Facilitate use-case workshops that translate questions like who accessed an application, what administrative changes occurred, whether privileged access was elevated, and which high-risk events require notification into Splunk content.
  • Test alerts and dashboards with stakeholders, tune thresholds and logic, reduce false positives, and document expected behavior, ownership, response procedures, and escalation paths.
  • Identify sensitive information in logs and coordinate with data owners and security partners to address masking, minimization, access, and retention requirements before production use.
  • Troubleshoot onboarding issues involving connectivity, stale or missing data, log permissions, malformed events, unsupported platforms, add-on compatibility, and application-side configuration.
  • Maintain onboarding status, risks, decisions, blockers, metrics, and technical documentation in the organization’s ticketing and knowledge-management systems.
  • Create runbooks, data dictionaries, dashboard guides, alert specifications, validation evidence, and support documentation that enable sustainable ownership.
  • Provide demonstrations, knowledge transfer, and practical Splunk guidance to application teams so they can effectively use the content delivered for them.
  • Support continuous improvement of onboarding standards, intake forms, reusable templates, quality gates, and automation.

Requirements

  • Experience using Splunk Enterprise or Splunk Cloud to search, analyze, visualize, and alert on machine data.
  • Honed hands-on proficiency with Search Processing Language, including filtering, aggregation, field extraction, lookups, time-based analysis, joins or alternatives, and performance-conscious search design.
  • Hands-on experience building production dashboards, alerts, reports, and scheduled searches for technical or business stakeholders.
  • Experience coordinating technical work across application owners, engineering teams, infrastructure teams, security teams, vendors, and project stakeholders.
  • Working knowledge of log collection and transport concepts such as agents or forwarders, syslog, REST APIs, databases, cloud services, queues or event streams, and structured data formats.
  • Ability to review sample events, recognize data-quality issues, identify useful fields, and explain logging gaps in clear business language.
  • Strong troubleshooting skills across applications, operating systems, networks, identity, permissions, and data pipelines.
  • Strong written and verbal communication skills, including the ability to lead discovery sessions, document decisions, explain technical constraints, and manage follow-up actions.
  • Ability to manage multiple concurrent onboarding efforts and content-development requests while maintaining accurate status and documentation.
  • Sound judgment when handling sensitive data and access-controlled information.

Qualifications

  • Experience with Splunk Enterprise Security, Splunk IT Service Intelligence, or comparable security and operational analytics platforms.
  • Experience with the Splunk Common Information Model, data models, accelerated searches, macros, event types, tags, and knowledge-object governance.
  • Experience with Splunk configuration concepts such as inputs, outputs, props, transforms, indexes, deployment apps, roles, and add-ons.
  • Familiarity with Linux and Windows logging, cloud and SaaS audit logs, Microsoft Azure, databases, identity platforms, network devices, and enterprise applications.
  • Experience designing security detections, fraud-monitoring content, compliance reporting, application-health dashboards, or operational key performance indicators.
  • Knowledge of software development or configuration-management practices, including source control, peer review, testing, release management, and change control.
  • Experience with scripting or automation using Python, PowerShell, shell scripting, REST APIs, or orchestration platforms.
  • Understanding of data protection, least privilege, data retention, audit logging, regulatory requirements, and secure handling of sensitive log data.
  • Experience in banking, financial services, healthcare, government, or another regulated environment.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Security+, or equivalent practical experience.

Similar jobs