Job Description
Job Description
At Zotec Partners, our People make it happen.
Transforming the healthcare industry isn't easy. But when you build a team like the one we have, that goal can become a reality. Our accomplishments can't happen without our extraordinary people – the men and women across the country who make up our diverse Zotec family and help make this company a best place to work.
Over 25 years ago, we started Zotec with a clear vision, to partner with physicians to simplify the business of healthcare. Today we are more than 900 employees strong and we continue to use our incredible talent and energy to bring that vision to life. We are a team of Innovators, Collaborators and Doers.
We're seeking a Splunk Security Engineer to join us.
This is a hands-on technical role where you'll serve as Zotec's Splunk Subject Matter Expert. You'll maintain our Splunk infrastructure (Enterprise, ES, ITSI, and Cloud) while enabling teams across the organization to leverage Splunk effectively.
What you'll do :
Platform Administration (Primary Focus)
- Manage Splunk Enterprise clusters, deployment servers, and forwarders
- Troubleshoot platform issues : performance, parsing failures, forwarder connectivity
- Configure data inputs and optimize license usage
- Plan and execute upgrades and maintain system health
- Create and maintain props.conf, transforms.conf, and other configurations
Technical Leadership & Training
Serve as the company-wide Splunk SME and technical advisorTrain users across Security, IT Operations, and Application teamsDevelop training materials and best practices documentationProvide guidance on dashboard creation and search optimizationBuild self-service capabilities for non-security teamsSecurity Operations Support
Implement detection rules created by Security Detection Engineers in Splunk ESBuild and optimize security dashboards for SOC useEnsure data models maintain CIM complianceProvide tier 3 Splunk support during incidentsTune search performance while maintaining detection accuracyData Management
Onboard new data sources using forwarders, HEC, and technical add-onsDevelop parsing rules for custom log formatsTroubleshoot ingestion issues and data quality problemsWork with development teams on logging standardsWhat you'll bring to Zotec :
Must Have :
3+ years hands-on Splunk administration experience (not just user experience)Proven expertise with distributed Splunk architecturesStrong SPL and regex skills for complex queries and parsingExperience with Splunk ES or ITSI administrationLinux / Unix command line proficiencyAbility to explain technical concepts to diverse audiencesPreferred :
Splunk certifications (Admin, Architect, ES Admin)Python or PowerShell scripting experienceSplunk Cloud experienceExperience training technical and non-technical usersKey Indicators of Fit :
You've managed indexer and search head clustersYou understand Splunk configuration file precedenceYou can optimize searches that are impacting performanceYou enjoy teaching others and sharing knowledgeYou're comfortable with on-call rotation for critical issuesAt Zotec, you will enjoy a network of highly experienced professionals in an environment where you can operate with autonomy yet have the resources and backing of other professionals in a similar role. Entrepreneurial and enterprising is the spirit of our team. If you are an original thinker and opportunity seeker, we'd like to talk to you!
Learn more about our organization, by visiting us at www.zotecpartners.com
E-Verify and Equal Opportunity Employer
Powered by JazzHR
0zy6uP0NHk