Splunk Architect Lead

Posted 3 Days Ago
Be an Early Applicant
Portland, OR, USA
In-Office
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The Splunk Architect Lead oversees the architecture and implementation of Splunk for cybersecurity monitoring and incident response, providing technical leadership and ensuring platform reliability and integration across environments.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Splunk Architect Lead to work in our Portland, OR office.  Please Note: This position is contingent upon contract award.

 

The Splunk Architect and Lead is responsible for defining, guiding, and overseeing the architecture, implementation, optimization, and governance of Splunk capabilities that support cybersecurity monitoring, threat detection, incident response, reporting, and enterprise security operations. This role provides technical leadership for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, and related integrations across complex operational environments. 

The ideal candidate combines deep Splunk architecture expertise, hands-on engineering experience, security operations knowledge, and leadership ability to guide engineers, analysts, stakeholders, and vendors. This role establishes scalable designs, enforces technical standards, ensures platform reliability, and translates mission and SOC requirements into secure, maintainable, and operationally effective Splunk solutions. 

 

Key Responsibilities 

Splunk Architecture & Strategy 

  • Define and maintain the target Splunk architecture, including indexer clusters, search head clusters, deployment servers, heavy forwarders, universal forwarders, apps, add-ons, integrations, storage, and high-availability components. 
  • Develop technical roadmaps, architecture recommendations, implementation plans, and modernization strategies for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or hybrid Splunk environments. 
  • Ensure Splunk architecture supports SOC operations, security monitoring, incident response, compliance reporting, data retention, scalability, resilience, and performance requirements. 
  • Assess current-state capabilities, identify architectural gaps, and recommend improvements aligned to program priorities, operational needs, and cybersecurity best practices. 

Technical Leadership & Governance 

  • Serve as the technical lead for Splunk engineering activities, providing direction, review, and mentorship to Splunk engineers, security engineers, analysts, and other technical contributors. 
  • Establish and enforce Splunk standards for index naming, sourcetypes, field extractions, Common Information Model alignment, knowledge objects, access controls, app deployment, configuration management, and change control. 
  • Review major design decisions, configuration changes, content deployments, and integration approaches for technical soundness, maintainability, security, and operational impact. 
  • Coordinate Splunk engineering priorities, assign technical work as needed, and ensure deliverables are completed accurately, consistently, and on schedule. 

Platform Design, Scalability & Reliability 

  • Lead design efforts for platform performance, capacity, storage, retention, data lifecycle management, search concurrency, licensing, disaster recovery, backup, and high availability. 
  • Oversee platform health monitoring, performance tuning, system optimization, upgrade planning, patching strategies, and long-term maintenance planning. 
  • Guide troubleshooting of complex issues involving ingestion delays, parsing problems, skipped or dropped data, search performance, data model acceleration, app conflicts, and infrastructure dependencies. 
  • Partner with infrastructure, cloud, network, identity, endpoint, and system administration teams to ensure Splunk architecture integrates securely and reliably with the broader environment. 

Data Architecture & Integration Oversight 

  • Define data onboarding architecture and integration patterns for security, infrastructure, cloud, endpoint, network, identity, application, vulnerability, and operational data sources. 
  • Oversee normalization, parsing, field extraction, data routing, index design, retention settings, source coverage, and Splunk Common Information Model implementation. 
  • Prioritize data source onboarding based on mission value, SOC use cases, detection requirements, compliance needs, and platform capacity constraints. 
  • Ensure integrations with EDR, NDR, firewalls, IDS/IPS, proxy, DNS, cloud platforms, identity providers, ticketing systems, SOAR platforms, and case management tools are secure, reliable, and supportable. 

Security Analytics & SOC Enablement 

  • Translate SOC, threat hunting, threat intelligence, incident response, and leadership requirements into Splunk architecture, data, dashboard, reporting, and detection engineering capabilities. 
  • Provide technical guidance for correlation searches, notable event rules, dashboards, reports, risk-based alerting, data models, content packs, and security monitoring use cases. 
  • Support detection tuning, alert fidelity improvement, false-positive reduction, source coverage analysis, and monitoring gap remediation in coordination with SOC leadership and analysts. 
  • Ensure Splunk content and data capabilities support timely triage, investigation, evidence retrieval, event reconstruction, and operational reporting. 

Implementation Oversight & Quality Assurance 

  • Lead or oversee implementation activities for Splunk platform components, integrations, apps, add-ons, dashboards, reports, alerts, and security content. 
  • Validate engineering work products, test plans, deployment packages, configuration changes, and operational procedures before release into production environments. 
  • Ensure Splunk changes follow approved change management, configuration management, testing, documentation, and rollback processes. 
  • Coordinate with vendors, product support, and external technical teams to resolve complex issues and evaluate new capabilities. 

Stakeholder Engagement & Program Support 

  • Act as the primary technical point of contact for Splunk architecture, platform strategy, implementation risks, technical dependencies, and capability planning. 
  • Brief program leadership, SOC leadership, technical teams, and stakeholders on Splunk status, risks, roadmap items, architectural decisions, and recommended investments. 
  • Translate complex Splunk platform issues, data coverage gaps, and technical tradeoffs into clear operational and business language. 
  • Support planning, estimation, schedule coordination, status reporting, and prioritization for Splunk-related initiatives. 

Documentation, Standards & Continuous Improvement 

  • Develop and maintain architecture diagrams, engineering standards, design documents, runbooks, operational procedures, troubleshooting guides, and technical decision records. 
  • Maintain governance for knowledge object management, role-based access, app lifecycle management, source onboarding, dashboard standards, and detection content lifecycle processes. 
  • Evaluate emerging Splunk features, apps, add-ons, integrations, automation approaches, and security analytics practices to improve reliability, efficiency, and mission value. 
  • Mentor technical staff and promote consistent Splunk engineering practices, SPL development standards, data quality expectations, and operational discipline. 
Preferred Qualifications
  • 7+ years of experience in cybersecurity engineering, SIEM architecture, security operations, infrastructure engineering, or related technical roles. 
  • 5+ years of hands-on Splunk administration, engineering, implementation, or architecture experience in enterprise, mission-critical, or security operations environments. 
  • Proven experience designing, leading, or supporting complex Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or distributed Splunk environments. 
  • Strong understanding of Splunk architecture, including indexers, search heads, deployment servers, forwarders, apps, add-ons, indexes, sourcetypes, knowledge objects, permissions, data models, and licensing. 
  • Demonstrated experience with data onboarding, parsing, field extraction, normalization, Common Information Model alignment, dashboards, reports, correlation searches, and SPL development. 
  • Experience leading technical teams, reviewing engineering work products, establishing standards, and coordinating complex implementation or optimization activities. 
  • Understanding of SOC operations, incident response, threat hunting, detection engineering, cybersecurity data sources, and security monitoring use cases. 
  • Strong written and verbal communication skills, including the ability to brief technical and non-technical stakeholders on architecture, risks, priorities, and recommendations. 

Skills Required

  • 7+ years of experience in cybersecurity engineering or SIEM architecture
  • 5+ years of hands-on Splunk administration, engineering, or architecture experience
  • Proven experience designing, leading or supporting complex Splunk environments
  • Strong understanding of Splunk architecture
  • Demonstrated experience with data onboarding and SPL development
  • Experience leading technical teams and establishing standards
  • Understanding of SOC operations and cybersecurity monitoring use cases
  • Strong written and verbal communication skills

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Optum Logo Optum

Registered Nurse

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Clackamas, OR, USA
160000 Employees
39-59 Hourly

Optum Logo Optum

Primary Care (FM/IM) Physician, Corvallis

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Corvallis, OR, USA
160000 Employees
226K-366K Annually

Optum Logo Optum

Medical Assistant - Eugene, OR

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Eugene, OR, USA
160000 Employees
16-29 Hourly

MongoDB Logo MongoDB

Technical Services Engineer 2nd Shift

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
5 Locations
5550 Employees
90K-176K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account