Splunk Platform Engineer
XPT Software Australia PtyListed 24 Sep 2026
Splunk Platform Engineer
We are seeking an experienced Splunk Platform Engineer to
manage and support a distributed Splunk environment hosted on AWS.
Key Responsibilities
- Administer
Splunk Search Head and Indexer clusters, Deployers, Deployment Servers, Forwarders,
and supporting components.
- Monitor
and troubleshoot platform health, performance, data ingestion, storage,
searches, and alerts.
- Onboard
log sources and configure inputs, parsing, timestamps, indexes, retention,
and access controls.
- Plan
and execute Splunk upgrades, migrations, patching, vulnerability
remediation, and compatibility testing.
- Support
AWS-based Splunk infrastructure and S3/Glacier log archival.
- Manage
incidents, problems, changes, root-cause analysis, and operational
documentation.
- Work
with security, cloud, infrastructure, application, and vendor teams.
Required Skills
- Strong
knowledge of Splunk architecture and distributed environments.
- Hands-on
experience with Splunk administration, clustering, upgrades, migrations,
and troubleshooting.
- Experience
with Linux, particularly RHEL and Amazon Linux.
- Working
knowledge of AWS services, including EC2, S3, IAM, VPC, Subnets, Security
Groups, and CloudWatch.
- Proficiency
in Python, Bash, or Shell scripting.
- Strong
communication, documentation, and stakeholder-management skills.
Desirable Experience
- Splunk
Enterprise Security, Splunk Cloud, or Splunk SOAR.
- ServiceNow
or Jira and ITIL-based service-management processes.
- Security
compliance, audit evidence, and vulnerability management.
Certifications – Optional
- Splunk
Enterprise Certified Admin or Architect.
- AWS
Certified Solutions Architect – Associate or Professional.
- Relevant
Red Hat, Terraform, Ansible, ITIL, or security certification.