9 april 2026 Development / Programming Splunk Amsterdam ZZP and / or Contracting

Introduction

  • 36 hours a week
  • Start: ASAP
  • Duration: 1 year with possible extension
  • Hybrid work.
  • ZZP: Yes

Function

We are seeking a Splunk Platform Engineer to own, operate, and optimize our on-prem and hybrid Splunk platform, supporting enterprise logging, security monitoring (SIEM), and observability capabilities.
This role is responsible for ensuring the availability, performance, scalability, and cost-efficiency of the Splunk environment, while enabling Security Operations, IT Operations, and Application teams with reliable, high-quality telemetry and actionable insights.
 
With the following results (SMART)
 
Architect, deploy, and manage on-prem Splunk Enterprise environments, including:
• Indexer clusters
• Search Head clusters
• Heavy and Universal Forwarders
• Deployment Server and License Manager
• Ensure high availability, disaster recovery, and platform resilience
• Perform version upgrades, patching, and lifecycle management

Data Engineering & Optimization
• Design and maintain index strategies, retention policies, and tiered storage (hot/warm/cold/frozen)
• Control ingestion volume through filtering, routing, and parsing optimization
• Ensure Common Information Model (CIM) compliance and data model acceleration efficiency
• Optimize search performance, dashboard load times, and resource utilization

Security & SIEM Enablement
• Operate and tune Splunk Enterprise Security (ES)
• Implement correlation searches, risk-based alerting, and notable event workflows
• Maintain threat detection coverage aligned to MITRE ATT&CK
• Support audits, compliance reporting, and SOC operations

Observability & Hybrid Integration
• Integrate Splunk Observability Cloud with on-prem Splunk Enterprise
• Enable APM, infrastructure monitoring, and telemetry correlation across hybrid environments
• Support Kubernetes, cloud workloads, and application telemetry pipelines

Governance & Cost Management
• Manage Splunk licensing, ingestion forecasting, and capacity planning
• Implement data governance and compliance controls
• Track and report platform KPIs to leadership and stakeholders

Requirements

Relevant knowledge, skills, competences & desired education level
 
Splunk Platform Engineering
• Splunk Enterprise architecture (on-prem & hybrid)
• Indexer clustering & Search Head clustering
• Forwarder management & deployment server configuration
• License management & ingestion forecasting
• Backup, DR, and multi-site clustering

Data Optimization & Performance
• Index design and retention lifecycle management
• SPL performance tuning and search optimization
• Data Model Acceleration (DMA) and CIM mapping
• Storage tiering and cold/frozen data management
• Parsing, filtering, and routing (props/transforms)

SIEM & Security
• Splunk Enterprise Security (ES)
• Risk-Based Alerting (RBA)
• Threat framework mapping (MITRE ATT&CK)
• SOC process integration and compliance reporting

Observability & Telemetry
• Splunk Observability Cloud
• OpenTelemetry pipelines
• APM and Infrastructure Monitoring
• Hybrid cloud telemetry integration

Systems & Automation
• Linux & Windows server administration
• Virtualization and storage platforms
• Scripting (Python, Bash, PowerShell)
• Infrastructure as Code (Ansible, Terraform – preferred)

Information

Jobs A2Z-CM +31(0)20-3337629

Application

Jobs A2Z-CM +31(0)20-3337629

Your contact

Inlichtingen

Jobs A2Z-CM +31(0)20-3337629

Vacancy number

4013