22 Sep
|
PlanIT Search
|
Toronto
22 Sep
PlanIT Search
Toronto
Employment Type:
Contract, 12 months to start Work arrangement : 4 days onsite per week Only candidates legally eligible to work in Canada without the need for visa sponsorship will be contacted We are looking for an experienced
Senior Splunk Engineer
to join our client on a 12-month contract with potential for extension. This is a hands‑on engineering role for someone who has strong experience supporting enterprise‑scale Splunk environments, with a particular focus on
data onboarding, Splunk Enterprise Security (ES), CIM, security use cases, and platform engineering . The ideal candidate will be comfortable working independently while partnering closely with security, infrastructure, application, and business teams to design, implement, troubleshoot, and optimize Splunk solutions. What You’ll Do
Lead end‑to‑end
Splunk data onboarding , from requirements analysis and ingestion design through implementation, validation, optimization, and troubleshooting. Onboard diverse and high-volume data sources, including application logs, servers, databases, network/security devices, syslog, APIs, and cloud platforms. Configure and troubleshoot Splunk ingestion and parsing using
inputs.conf, outputs.conf, props.conf, transforms.conf, and indexes.conf . Work with
Universal Forwarders, Heavy Forwarders, and HTTP Event Collector (HEC) . Configure sourcetypes, indexes, timestamps, event parsing, filtering, routing, and field extractions. Troubleshoot data quality, ingestion, parsing, and field extraction issues. Normalize security data using the
Splunk Common Information Model (CIM) , including field mappings, tags, event types,
and data models. Develop and enhance
Splunk Enterprise Security (ES)
use cases, correlation searches, detections, alerts, dashboards, reports, and SPL searches. Tune searches, detections, dashboards, and scheduled jobs to improve performance, accuracy, and reduce false positives. Configure, maintain, monitor, and troubleshoot distributed and clustered Splunk environments. Monitor ingestion pipelines, indexing/search performance, resource utilization, platform health, and capacity. Perform root-cause analysis and
Splunk performance tuning . Create and maintain technical documentation, configuration standards, onboarding procedures, and operational runbooks. Collaborate with security, infrastructure, application, and business stakeholders to deliver effective Splunk solutions. What We’re Looking For
Extensive hands‑on experience as a
Splunk Engineer / Senior Splunk Engineer
in enterprise‑scale environments. Strong experience with
Splunk data onboarding , including complex and high-volume data sources. Proven experience with
Splunk Enterprise Security (ES)
and security use‑case/detection development. Solid knowledge of
Splunk CIM , including normalization, field mapping, tags, event types, and data models.
Deep understanding of Splunk architecture, ingestion, parsing, indexing, forwarding, search, and distributed environments. Universal/Heavy ForwardersStrong
SPL
development and optimization skills. Experience developing dashboards, reports, alerts, correlation searches, and security use cases. Hands‑on experience with Splunk platform configuration, maintenance, monitoring, troubleshooting, and performance tuning. Working knowledge of
Linux/Unix, networking, APIs, regex, and common log/data formats . Python and/or Shell scripting and automation experience is an asset. Strong analytical and problem‑solving skills with the ability to independently troubleshoot complex technical issues. Excellent written and verbal communication skills. Certifications & Nice-to-Haves
Splunk certifications such as
Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect , or relevant Splunk ES certifications are an asset. PlanIT is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided based on qualifications, merit, and business needs. Disclosure:
This posting represents an active and genuine vacancy with one of Plan IT’s clients and is not intended for speculative or pipeline recruitment. Plan IT and/or its clients may use AI‑assisted tools from time to time to support the screening and evaluation of applications; however, these tools do not replace human judgment or decision‑making at any stage of the hiring process.
#J-18808-Ljbffr
📌 Senior Splunk Engineer (Toronto)
🏢 PlanIT Search
📍 Toronto