Location: Remote within North America, working EST hours
Language: Strong written and spoken English communication skills
Duration: 12-month contract, with potential for extension
About the Opportunity
This is an exciting opportunity for an experienced Splunk Engineer to support complex, enterprise-scale environments within a leading professional services organization. You’ll take a hands-on role in data onboarding, security use cases, platform optimization, and troubleshooting, helping teams get more value from their Splunk environment.
You’ll work closely with security, application, infrastructure, and business teams to deliver scalable solutions that support critical operational and security needs. This role is well suited to someone who enjoys independently solving complex technical challenges while collaborating with diverse stakeholders.
What’s In It for You
You’ll contribute to highly technical, meaningful projects while working alongside skilled professionals across multiple disciplines. You’ll also gain exposure to enterprise technology, security engineering, and complex Splunk environments, with opportunities to strengthen your expertise and work flexibly in a remote setting.
Your Responsibilities
• You’ll lead end-to-end Splunk data onboarding, from requirements and ingestion design through implementation, validation, optimization, and troubleshooting.
• You’ll configure ingestion and parsing using HEC, Universal and Heavy Forwarders, inputs.conf, outputs.conf, props.conf, transforms.conf, and indexes.conf.
• You’ll normalize security data to Splunk CIM, including field mappings, tags, event types, and data models.
• You’ll develop Splunk ES use cases, correlation searches, detections, alerts, dashboards, reports, and SPL searches.
• You’ll monitor platform health, ingestion, indexing and search performance, capacity, and resource utilization.
• You’ll troubleshoot complex platform issues, perform root-cause analysis, and optimize enterprise Splunk environments.
• You’ll maintain configuration standards, onboarding documentation, procedures, and operational runbooks.
Skills and Qualifications
• Extensive hands-on Splunk Engineer experience within enterprise-scale environments, including complex, high-volume data onboarding.
• Strong Splunk Enterprise, Splunk ES, SPL, CIM, distributed environment, indexing, forwarding, parsing, and search expertise.
• Hands-on experience with Linux/Unix, networking, APIs, Regex, log formats, HEC, Splunk configuration files, dashboards, reports, and alerts.
• Strong analytical, troubleshooting, communication, and cross-functional collaboration skills.
• Python or Shell scripting, automation, ITSI, AWS/Azure/GCP, SIEM/security operations, and CI/CD experience are assets.
• Splunk Enterprise Certified Admin, Certified Architect, ES, or other relevant Splunk certifications are considered assets.
Why Partner with Altis
If you’ve never worked with a staffing agency before, we make it easy. We work with top employers across Canada who have great jobs to fill, each vetted and verified by our team. When you apply for a job with Altis, we get to know you as a candidate and learn what your strengths are. Then, if you’re a solid match, we handle all the logistics, advocating for you as a candidate for the role, providing access to coaching and connecting you directly with the hiring manager. And rest assured, all our services are free of cost for candidates.