Splunk SME SRFWe are seeking an experienced Splunk Subject Matter Expert to lead the design, implementation, and optimization of Splunk solutions across security operations and observability domains. This role serves as the technical authority on Splunk architecture, driving enterprise-wide deployments for security monitoring, threat detection, and comprehensive observability across hybrid and multi-cloud environments.
Design and implement Splunk Enterprise Security (ES) deployments including correlation searches, notable event management, risk-based alerting, and threat intelligence framework integration
Develop and optimize security use cases covering MITRE ATT&CK tactics, insider threat detection, anomaly detection, and APT hunting
Build Splunk SOAR playbooks for security orchestration, automated response workflows, and cross-platform integrations
Implement User and Entity Behavior Analytics (UBA) to detect insider threats, compromised credentials, and behavioral anomalies
Architect and deploy Splunk Observability Cloud solutions including Infrastructure Monitoring, APM, RUM, and Log Observer
Implement OpenTelemetry instrumentation for distributed tracing, metrics, and correlation across microservices
Build synthetic monitoring and alerting strategies for proactive detection of performance and availability issues
Integrate diverse data sources across AWS, Azure, GCP, EDR tools, firewalls, IDS/IPS, network devices, applications, and databases
Design API integrations, webhook configurations, and custom scripted inputs for specialized collection needs
Implement Splunk HEC with load balancing, encryption, and token governance
Develop custom TAs and applications to extend Splunk capabilities
Lead technical discovery workshops and design target-state Splunk architectures
Develop architecture diagrams, implementation guides, runbooks, and knowledge transfer materials
Provide mentorship on Splunk administration, SPL optimization, dashboards, and alerts
Manage POCs and pilots demonstrating Splunk s value across security and observability
Serve as escalation point for complex technical and architectural issues
7 10 years experience with Splunk Enterprise, including 3+ in architect or senior admin roles
Deep expertise in Splunk Enterprise Security and SOC solution design
Strong experience with Splunk Observability Cloud including APM, Infra Monitoring, and RUM
Advanced SPL skills including optimized queries, regex, field extraction, and CIM mapping
Experience with Splunk SOAR automation and orchestration
Strong understanding of MITRE ATT&CK, NIST CSF, and Kill Chain methodologies
Experience with PCI-DSS, HIPAA, GDPR, SOC 2, and ISO 27001 compliance monitoring
Knowledge of threat intelligence platforms, IOC management, and threat hunting
Experience with AWS, Azure, GCP native logging, security monitoring, and cost optimization
Understanding of Docker, Kubernetes, microservices, and cloud-native observability
Knowledge of networking concepts, firewalls, proxies, IDS/IPS, VPNs, zero-trust architecture
Familiarity with CI/CD, Terraform, CloudFormation, and DevOps practices
Proficiency in Python for automation, API integrations, and Splunk app development
Experience with Bash or PowerShell for automation and data collection
Understanding of REST APIs, JSON/XML, and web technologies
Splunk Certified Architect or ES Certified Admin
Certifications such as CISSP, GCIA, GCIH, GCFA
Experience with Splunk MLTK for anomaly detection and predictive analytics
Experience with managed Splunk services and 24x7 operations
Knowledge of Datadog, New Relic, or Dynatrace
Experience with OT/IoT security monitoring
Excellent communication skills and ability to translate technical concepts for business stakeholders
Strong analytical and problem solving abilities
Ability to manage multiple concurrent client engagements
Independent working style with effective collaboration across distributed teams
Customer focused mindset with a commitment to quality
Splunk Certified Architect or ES Certified Admin
Certifications such as CISSP, GCIA, GCIH, GCFA
Experience with Splunk MLTK for anomaly detection and predictive analytics
Experience with managed Splunk services and 24x7 operations
Knowledge of Datadog, New Relic, or Dynatrace
Experience with OT/IoT security monitoring
7 10 years experience with Splunk Enterprise, including 3+ in architect or senior admin roles
Deep expertise in Splunk Enterprise Security and SOC solution design
Strong experience with Splunk Observability Cloud including APM, Infra Monitoring, and RUM
Advanced SPL skills including optimized queries, regex, field extraction, and CIM mapping
Experience with Splunk SOAR automation and orchestration

Keyskills: Architect Administration Automation XML SOC ISO 27001 JSON Load balancing IPS Python
Zensar Technologies Limited Zensar Technologies is among the top 25 software and BPO services providers in India. It is an RPG Group company. Headquartered in India, Zensar Technologies has marketing presence in US, Europe and Asia Pacific regions. The company has operations and a customer bas...