Summary
✨ AI‑Generated
Take primary technical ownership of a security monitoring platform, managing enterprise and cloud deployments, clusters, upgrades, data integrations, parsing, normalization, and performance. You will help maintain a highly available and reliable SIEM environment within a security operations team.
Highlights
Own and optimize critical security monitoring infrastructure, including deployment, administration, clustering, data onboarding, upgrades, troubleshooting, and performance. The role provides substantial technical ownership within a security operations environment.
Description
Splunk Security Infrastructure Engineer (Splunk Administrator)
Location: Doha, Qatar
Contract: 12 Months – Yearly Renewable
We are looking for a Splunk Security Infrastructure Engineer to manage and support Splunk environments within the Security Operations team.
The Splunk Administrator is responsible for the deployment, configuration, administration, and optimization of the organization's Splunk Enterprise and Splunk Cloud environments.
This role serves as the primary technical owner of the Splunk platform within the Security Operations (SecOps) team, ensuring high availability, data integrity, and peak performance of the SIEM ecosystem.
Key Responsibilities
Day-to-day Splunk administration and engineering.
Onboard and integrate new data sources.
Manage Search Head & Indexer Clusters.
Perform Splunk upgrades, configuration, troubleshooting, and optimization.
Handle parsing, regex, field extractions, data models, and normalization.
Ensure data is CIM-compliant.
Support Splunk Enterprise Security (ES) and security monitoring.
Requirements
3–5 years of hands-on experience in Splunk administration, SIEM engineering, or Security Operations.
Strong hands-on experience with Splunk clustering, onboarding, upgrades, and troubleshooting.
At least one Splunk Administration certification is mandatory.
Good communication and problem-solving skills.
Academic & Professional Qualifications
Bachelor’s degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent.
Splunk Core Certified Power User – Required.
Splunk Enterprise Certified Admin – Required.
Splunk Enterprise Security Certified Admin – Preferred.
Splunk SOAR Certified Automation Developer – Preferred.
Preferred security certifications: CompTIA Security+, CySA+, CEH, CISSP, or GCI
Interested candidates can share their updated CV to surjith.cm@linnk.com