Senior Splunk Engineer (Toronto)

Senior Splunk Engineer (Toronto)

15 Sep
|
PlanIT Search
|
Toronto

15 Sep

PlanIT Search

Toronto

Location: Toronto, ON

Employment Type: Contract, 12 months to start

Work arrangement : 4 days onsite per week

Only candidates legally eligible to work in Canada without the need for visa sponsorship will be contacted

We are looking for an experienced Senior Splunk Engineer to join our client on a 12-month contract with potential for extension. This is a hands-on engineering role for someone who has strong experience supporting enterprise-scale Splunk environments, with a particular focus on data onboarding, Splunk Enterprise Security (ES), CIM, security use cases, and platform engineering .

The ideal candidate will be comfortable working independently while partnering closely with security, infrastructure, application, and business teams to design, implement, troubleshoot, and optimize Splunk solutions.

What You'll Do

- Lead end-to-end Splunk data onboarding , from requirements analysis and ingestion design through implementation, validation, optimization, and troubleshooting.
- Onboard diverse and high-volume data sources, including application logs, servers, databases, network/security devices, syslog, APIs, and cloud platforms.
- Configure and troubleshoot Splunk ingestion and parsing using inputs.conf, outputs.conf, props.conf, transforms.conf, and indexes.conf .
- Work with Universal Forwarders, Heavy Forwarders, and HTTP Event Collector (HEC) .
- Configure sourcetypes, indexes, timestamps, event parsing, filtering, routing, and field extractions.
- Troubleshoot data quality, ingestion, parsing, and field extraction issues.
- Normalize security data using the Splunk Common Information Model (CIM) , including field mappings, tags, event types,



and data models.
- Develop and enhance Splunk Enterprise Security (ES) use cases, correlation searches, detections, alerts, dashboards, reports, and SPL searches.
- Tune searches, detections, dashboards, and scheduled jobs to improve performance, accuracy, and reduce false positives.
- Configure, maintain, monitor, and troubleshoot distributed and clustered Splunk environments.
- Monitor ingestion pipelines, indexing/search performance, resource utilization, platform health, and capacity.
- Perform root-cause analysis and Splunk performance tuning .
- Create and maintain technical documentation, configuration standards, onboarding procedures, and operational runbooks.
- Collaborate with security, infrastructure, application, and business stakeholders to deliver effective Splunk solutions.

What We're Looking For

- Extensive hands-on experience as a Splunk Engineer / Senior Splunk Engineer in enterprise-scale environments.
- Strong experience with Splunk data onboarding , including complex and high-volume data sources.
- Proven experience with Splunk Enterprise Security (ES) and security use-case/detection development.
- Strong knowledge of Splunk CIM , including normalization, field mapping, tags, event types, and data models.




- Deep understanding of Splunk architecture, ingestion, parsing, indexing, forwarding, search, and distributed environments.
- Universal/Heavy ForwardersStrong SPL development and optimization skills.
- Experience developing dashboards, reports, alerts, correlation searches, and security use cases.
- Hands-on experience with Splunk platform configuration, maintenance, monitoring, troubleshooting, and performance tuning.
- Working knowledge of Linux/Unix, networking, APIs, regex, and common log/data formats .
- Python and/or Shell scripting and automation experience is an asset.
- Robust analytical and problem-solving skills with the ability to independently troubleshoot complex technical issues.
- Excellent written and verbal communication skills.

Certifications & Nice-to-Haves Splunk certifications such as Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect , or relevant Splunk ES certifications are an asset.

PlanIT is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided based on qualifications, merit, and business needs.

Disclosure:

This posting represents an active and genuine vacancy with one of Plan IT’s clients and is not intended for speculative or pipeline recruitment. Plan IT and/or its clients may use AI-assisted tools from time to time to support the screening and evaluation of applications; however, these tools do not replace human judgment or decision-making at any stage of the hiring process.

📌 Senior Splunk Engineer (Toronto)
🏢 PlanIT Search
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior splunk engineer (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior splunk engineer (toronto) / toronto