Splunk Admin - Securities

4 - 8 years

10 - 18 Lacs

Posted:-1 days ago| Platform: Naukri logo

Apply

Skills Required

siem / soc operations soc splunk splunk enterprise security splunk administration splunk deployment & configuration security

Work Mode

Work from Office

Job Type

Full Time

Job Description

Splunk Engineer / Administrator Security Focus

Location:

CTC:

Experience:

Role Overview

Splunk Engineer/Administrator

Key Responsibilities

  • Splunk Administration & Engineering:

    • Install, configure, upgrade, and maintain Splunk Enterprise/Enterprise Security (ES).
    • Manage Splunk components (indexers, search heads, heavy/universal forwarders, deployment server).
    • Onboard data sources, parse logs, create field extractions, and optimize ingestion pipelines.
    • Ensure Splunk platform performance, availability, and scalability.
  • Security & Use Case Development:

    • Develop and enhance security use cases, alerts, dashboards, and correlation rules in Splunk.
    • Work closely with SOC teams to deploy detection logic, escalation rules, and threat hunting dashboards.
    • Perform security incident analysis and triage using Splunk ES.
  • Deployment & Integration:

    • Drive Splunk deployments for new use cases and applications across customer environments.
    • Collaborate with IT/security stakeholders to integrate Splunk with SIEM, SOAR, IAM, and other security tools.
  • Operations & Support:

    • Perform advanced troubleshooting of Splunk ingestion and search performance issues.
    • Automate admin tasks using scripting (Python, Shell, or PowerShell).
    • Support patching, upgrades, license management, and access control.
  • Collaboration & Innovation:

    • Partner with Deloitte internal teams and client stakeholders to deliver security-focused Splunk solutions.
    • Leverage industry best practices to improve Splunk adoption and optimize operational efficiency.

Must-Have Skills

  • 4+ years of IT experience with

    3+ years in Splunk administration/engineering

    .
  • Proven expertise in

    Splunk Enterprise/Enterprise Security administration

    (indexer/search head clustering, forwarder management, upgrades).
  • Strong knowledge of

    log ingestion, parsing, and data onboarding

    .
  • Hands-on experience in building

    security detections, dashboards, correlation rules

    .
  • Good understanding of

    security operations workflows

    (SOC, SIEM, incident response).
  • Proficiency with

    Linux/Unix environments

    and basic

    scripting

    (Python, Shell, PowerShell).
  • Excellent troubleshooting and performance tuning skills.

Good-to-Have Skills

  • Splunk Certified Admin / Architect / Power User.
  • Knowledge of

    cloud-hosted Splunk (AWS/Azure/GCP)

    .
  • Familiarity with SOAR tools (Phantom, XSOAR, etc.).
  • Exposure to enterprise security frameworks (MITRE ATT&CK, NIST, ISO 27001).

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
4AT Consulting logo
4AT Consulting

Consulting

Tech City

RecommendedJobs for You