18 Aug
|
AceStack
|
Toronto
Job Title: Splunk Engineer L3 Location: Toronto, ON Work Mode: Onsite Employment Type: Full time Job Description: Provide L3 engineering and administration support for enterprise Splunk and SIEM environments Design, implement, maintain, and optimize enterprise Splunk solutions across security monitoring and observability platforms Work extensively with Splunk Enterprise, Splunk ITSI, UBA, CRIBL, and related security and monitoring technologies Support Microsoft Security solutions including Microsoft Sentinel and integrate SIEM capabilities across enterprise environments Apply advanced knowledge of Splunk architecture, administration, configuration, troubleshooting, performance tuning, and optimization Develop and maintain Splunk solutions aligned with enterprise security, monitoring, governance, and operational requirements Ensure CIM compliance and implement consistent data models, field extractions, normalization, and data quality standards Design and maintain advanced Splunk dashboards, alerts, reports, searches, and monitoring solutions Onboard and integrate APIs, databases, applications, and Splunk Base Apps into enterprise Splunk environments Support security monitoring across Azure, AWS, Google Cloud, virtualized environments, and highly distributed infrastructure Implement and support Microsoft security technologies and cloud security monitoring solutions Analyze Windows, RHEL/Unix, network, server, application, and security log formats and develop appropriate ingestion and parsing strategies Develop Python scripts and automation to improve Splunk administration, data onboarding, monitoring, and operational efficiency Troubleshoot complex Splunk, SIEM, ingestion, search,
performance, and integration issues at L3 level Collaborate with security, infrastructure, cloud, network, application, and operations teams to resolve complex technical issues Apply security best practices to cloud solutions operating within highly virtualized environments Support enterprise monitoring toolsets and advanced security technologies across hybrid and multi-cloud environments Maintain technical documentation, operational procedures, architecture standards, and troubleshooting runbooks Participate in continuous improvement initiatives to enhance SIEM capabilities, security visibility, automation, and operational resilience Required Qualifications: Advanced knowledge and hands-on experience with Enterprise Splunk applications and Splunk administration Strong experience with Splunk architecture, configuration, troubleshooting, performance optimization, dashboards, alerts, and reporting Advanced experience with Splunk CIM compliance and data normalization Strong experience with Azure Cloud and Microsoft Security solutions including Microsoft Sentinel Experience with Splunk ITSI, UBA, and CRIBL is highly desirable Strong understanding of cloud security within highly virtualized environments Expert knowledge of Windows and RHEL/Unix log formats Strong understanding of network, server, application, and security log formats Proficiency in Python scripting and automation Experience onboarding APIs, databases, applications, and Splunk Base Apps Strong troubleshooting, analytical, communication, and stakeholder collaboration skills Experience working within highly governed enterprise or financial services environments is preferred
📌 Splunk Engineer (Toronto)
🏢 AceStack
📍 Toronto