Splunk Engineer (contract) (Toronto)

Splunk Engineer (contract) (Toronto)

15 Sep
|
KPMG Canada
|
Toronto

15 Sep

KPMG Canada

Toronto

KPMG is an industry leading firm that serves clients on a variety of specialized projects that help them to work smarter, grow faster and compete better.

Why join our contract workforce?

- Interesting work: Deliver work that matters to you. We provide the opportunity to get involved in highly technical, complex and interesting projects where you can leverage your specific skillset and expertise to add value.
- Enrich your skills: Access to best-in-class technology, market intelligence and resources to advance your unique technical skills and expertise. Work alongside diverse, passionate and highly skilled professionals working together to drive innovation.
- Flexible opportunities: Find projects that match when and where you want to work.

The opportunity We are seeking a Splunk Engineer with strong hands-on experience supporting enterprise Splunk environments. The ideal candidate will have deep expertise in Splunk data onboarding, along with solid experience in Splunk Enterprise Security (ES), Common Information Model (CIM), use case development, SPL, dashboards and reports, platform configuration, performance tuning, monitoring, and troubleshooting. This is a hands-on engineering role requiring the ability to independently deliver Splunk solutions and work effectively with security, application, infrastructure, and business teams. This opportunity is for a 12 month contract with potential to extend, remote work is also possible during EST time zone.

What You Will Do

- Lead end-to-end Splunk data onboarding, including requirements analysis, ingestion design, implementation, validation, optimization, and troubleshooting.
- Onboard diverse data sources such as application logs, servers, databases, network/security devices, syslog, APIs, and cloud platforms.
- Configure and troubleshoot Splunk data ingestion and parsing using inputs.conf, outputs.conf, props.conf, transforms.conf, indexes.conf, HEC, and Universal/Heavy Forwarders.
- Configure sourcetypes, indexes, timestamps, event parsing, filtering, routing, and field extractions; troubleshoot data quality, ingestion, and parsing issues.




- Normalize and map security data to the Splunk Common Information Model (CIM), including field mappings, tags, event types, and data models.
- Develop and enhance Splunk Enterprise Security (ES) use cases, correlation searches/detections, alerts, dashboards, reports, and SPL searches.
- Fine-tune searches, detections, dashboards, and scheduled jobs to improve accuracy, reduce false positives, and optimize performance.
- Configure, maintain, monitor, and troubleshoot enterprise Splunk environments, including distributed and clustered Splunk components.
- Monitor platform health, ingestion pipelines, indexing/search performance, resource utilization, and capacity, and perform root-cause analysis and performance tuning.
- Maintain technical documentation, configuration standards, onboarding procedures, and operational runbooks.

Your Qualifications

- Extensive hands-on experience as a Splunk Engineer / Senior Splunk Engineer in enterprise-scale environments.
- Strong hands-on Splunk data onboarding experience is essential, including complex and high-volume data sources.
- Proven experience with Splunk Enterprise Security (ES) and developing security use cases and correlation searches/detections.
- In-depth knowledge of Splunk CIM, including data normalization, field mapping, tags, event types, and data models.
- Solid knowledge of Splunk architecture, ingestion, parsing, indexing, forwarding, search, and distributed environments.
- Practical experience with props.conf, transforms.conf, inputs.conf, outputs.conf, and indexes.conf.
- Proficiency in SPL development and optimization, dashboards, reports, alerts, and use cases.
- Hands-on experience with Splunk platform configuration, maintenance,



monitoring, performance tuning, and troubleshooting.
- Good understanding of Linux/Unix, networking, APIs, regex, and log/data formats
- Python/Shell scripting and automation experience is an asset.
- Excellent analytical and problem-solving skills with the ability to independently troubleshoot complex technical issues.
- Robust written and verbal communication skills and the ability to collaborate effectively across technical and business teams.

Certifications

- Splunk certifications such as Splunk Enterprise Certified Admin / Architect or relevant ES certification; experience with large-scale Splunk environments, ITSI, AWS/Azure/GCP, security operations/SIEM, and automation/CI/CD are considered assets.

- Primary Focus: Data Onboarding &
- CIM →
- Enterprise Security &
- Use Cases →
- Platform Engineering &
- Troubleshooting →
- Performance Tuning →
- SPL, Dashboards &
- Reporting

Our Values, The KPMG Way Integrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

For general recruitment-related inquiries, please contact the HR Delivery Centre at [email protected].

If you have a question about accessible employment at KPMG, or to begin a confidential conversation about your individual accessibility or accommodation needs through the recruitment process, we encourage you to contact us at [email protected] or phone: (phone hidden) or toll free 1-(phone hidden).

Pay Rate Range

75 - 85 CAD hourly

📌 Splunk Engineer (contract) (Toronto)
🏢 KPMG Canada
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (contract) (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (contract) (toronto) / toronto