Splunk Security Engineer
At Zotec Partners, our people make it happen. Transforming the healthcare industry isn't easy. But when you build a team like the one we have, that goal can become a reality. Our accomplishments can't happen without our extraordinary people the men and women across the country who make up our diverse Zotec family and help make this company a best place to work. Over 25 years ago, we started Zotec with a clear vision, to partner with physicians to simplify the business of healthcare. Today we are more than 900 employees strong and we continue to use our incredible talent and energy to bring that vision to life. We are a team of Innovators, Collaborators and Doers. We're seeking a Splunk Security Engineer to join us.
We are seeking a skilled Splunk Security Engineer to join our Information Security team. In this role, you will be responsible for the administration, optimization, and support of our Splunk environment, including Splunk Enterprise, Splunk IT Service Intelligence (ITSI), Splunk Enterprise Security (ES), and Splunk Cloud deployments. You will work closely with cross-functional teams to enhance our security monitoring capabilities, develop dashboards, create efficient searches, and ensure the reliability of our Splunk infrastructure.
What you'll do :
- Splunk Implementation and Maintenance
Administer and maintain our Splunk Enterprise environment and Splunk Cloud setup
Deploy, configure, and update Splunk Enterprise Security (ES) and IT Service Intelligence (ITSI)Coordinate and configure new Splunk resources as neededConfigure and secure Splunk endpointsInstall, configure, and update various Splunk applications and add-ons from SplunkbaseKeep Splunk and Splunkbase apps up to dateRun periodic health checks on Splunk systemsManage Splunk deployments to servers and workstationsUpdate user index permissionsDashboard and Search DevelopmentDesign, develop, optimize, and maintain Splunk dashboards, reports, and alerts
Create and refine search queries using SPL to improve detection capabilitiesDevelop custom visualization solutions to meet specific business requirementsCreate reusable dashboard components to ensure consistency across the environmentImplement role-based access controls for dashboards and reportsProvide training and support to end users on dashboard functionalityAssist team members with dashboard creation and search buildingExtract complex fields from different types of log files using regular expressionsData Ingestion and ManagementOnboard and integrate new data sources into the Splunk environment
Setup Splunk Technical Add-ons (TAs) for ingestionConfigure and implement HTTP Event Collector (HEC) tokensSetup proper parsing and field extractions for custom log typesValidate and refine Splunk license usage based on incoming logsWork with development teams to implement logging standards for custom applicationsSupport cloud-based ingestion from AWS, Google Cloud, and SaaS platformsTroubleshooting and SupportTroubleshoot Splunk-related issues and performance problems
Assist Security and Operations teams with incident investigations using SplunkProvide on-call support during security incidents and investigationsAssist with Universal Forwarder troubleshootingPerform analysis on log data and troubleshoot missing log errors from sourcesCollaboration and RequirementsParticipate in on-call rotation to support security investigations and assist with incidents as needed
Stay current with Splunk updates, security threats, and industry best practicesOther duties as assignedWhat you'll bring to Zotec :
3+ years of experience administering and supporting Splunk environmentsExperience with Splunk Enterprise Security (ES) and / or IT Service Intelligence (ITSI)Strong understanding of search processing language (SPL) and dashboard creationKnowledge of log sources, parsing, and normalization techniquesDetailed technical knowledge of database and operating system securityExperience with Linux / Unix, Windows, and MacOS operating systemsUnderstanding of network security concepts and security monitoringStrong analytical and problem-solving abilitiesExcellent communication and documentation skillsAbility to work under pressure and adapt to changing prioritiesDetail-oriented with strong organizational skillsTeam-oriented and skilled in working within a collaborative environmentAbility to prioritize tasks and manage time effectivelyProfessionally exercises discretion and independent judgment in day-to-day workPreferred :
Splunk certifications (Splunk Certified Admin, Architect, or similar)Experience with cloud environments (AWS, Azure, GCP)Experience integrating custom application logs and working with development teamsKnowledge of SIEM concepts and security frameworks (MITRE ATT&CK, NIST)Advanced dashboard development skills including JavaScript, CSS, and XMLScripting / programming experience (Python, PowerShell)Familiarity with web-related technologies and protocolsExperience with Splunk Observability and Smartstore deploymentsAt Zotec, you will enjoy a network of highly experienced professionals in an environment where you can operate with autonomy yet have the resources and backing of other professionals in a similar role. Entrepreneurial and enterprising is the spirit of our team. If you are an original thinker and opportunity seeker, we'd like to talk to you! Learn more about our organization.