Introduction
- 36 hours a week
- Start: ASAP
- Duration: 1 year with possible extension
- Hybrid work.
- ZZP: Yes
Function
We are seeking a Splunk Platform Engineer to own, operate, and optimize our on-prem and hybrid Splunk platform, supporting enterprise logging, security monitoring (SIEM), and observability capabilities.
This role is responsible for ensuring the availability, performance, scalability, and cost-efficiency of the Splunk environment, while enabling Security Operations, IT Operations, and Application teams with reliable, high-quality telemetry and actionable insights.
With the following results (SMART)
Architect, deploy, and manage on-prem Splunk Enterprise environments, including:
• Indexer clusters
• Search Head clusters
• Heavy and Universal Forwarders
• Deployment Server and License Manager
• Ensure high availability, disaster recovery, and platform resilience
• Perform version upgrades, patching, and lifecycle management
Data Engineering & Optimization
• Design and maintain index strategies, retention policies, and tiered storage (hot/warm/cold/frozen)
• Control ingestion volume through filtering, routing, and parsing optimization
• Ensure Common Information Model (CIM) compliance and data model acceleration efficiency
• Optimize search performance, dashboard load times, and resource utilization
Security & SIEM Enablement
• Operate and tune Splunk Enterprise Security (ES)
• Implement correlation searches, risk-based alerting, and notable event workflows
• Maintain threat detection coverage aligned to MITRE ATT&CK
• Support audits, compliance reporting, and SOC operations
Observability & Hybrid Integration
• Integrate Splunk Observability Cloud with on-prem Splunk Enterprise
• Enable APM, infrastructure monitoring, and telemetry correlation across hybrid environments
• Support Kubernetes, cloud workloads, and application telemetry pipelines
Governance & Cost Management
• Manage Splunk licensing, ingestion forecasting, and capacity planning
• Implement data governance and compliance controls
• Track and report platform KPIs to leadership and stakeholders
Requirements
Relevant knowledge, skills, competences & desired education level
Splunk Platform Engineering
• Splunk Enterprise architecture (on-prem & hybrid)
• Indexer clustering & Search Head clustering
• Forwarder management & deployment server configuration
• License management & ingestion forecasting
• Backup, DR, and multi-site clustering
Data Optimization & Performance
• Index design and retention lifecycle management
• SPL performance tuning and search optimization
• Data Model Acceleration (DMA) and CIM mapping
• Storage tiering and cold/frozen data management
• Parsing, filtering, and routing (props/transforms)
SIEM & Security
• Splunk Enterprise Security (ES)
• Risk-Based Alerting (RBA)
• Threat framework mapping (MITRE ATT&CK)
• SOC process integration and compliance reporting
Observability & Telemetry
• Splunk Observability Cloud
• OpenTelemetry pipelines
• APM and Infrastructure Monitoring
• Hybrid cloud telemetry integration
Systems & Automation
• Linux & Windows server administration
• Virtualization and storage platforms
• Scripting (Python, Bash, PowerShell)
• Infrastructure as Code (Ansible, Terraform – preferred)
Information
Jobs A2Z-CM +31(0)20-3337629
Application
Jobs A2Z-CM +31(0)20-3337629