Splunk Administrator
منذ 6 أيام
Dubai, Dubai Emirate, الإمارات العربية المتحدة
MindPool Technologies
دوام كامل
120,000 € - 160,000 € عقد
مجانًا عبر البريد الإلكتروني أو Google
احفظ هذه الوظيفة وحافظ على تنظيم بحثك
قم بإنشاء حساب مجاني لحفظ الوظائف وإنشاء التنبيهات والعودة إلى هذه القائمة من لوحة التحكم الخاصة بك.
مجانًا عبر البريد الإلكتروني أو Google
Job Title: Splunk Administrator (SIEM & Log Management) – MindPool Technologies – Dubai, UAE
Recruiting Company: MindPool Technologies. Job
Location:
Dubai United Arab Emirates.
Job Type
Full-Time. Application Method: Email CV to mano@mindpool-tech.com. Additional Info: Candidates able to join within 30 days or less are highly preferred; minimum 5+ years of experience required. Position Summary MindPool Technologies is seeking an experienced Splunk Administrator to manage, optimize, and support enterprise-scale Splunk environments. This role is critical in ensuring high-performance log management, security monitoring, data analytics, and SIEM operations across complex IT infrastructures. Detailed
Job Description
As a Splunk Administrator, you will be responsible for the architecture, administration, performance optimization, and ongoing management of Splunk platforms supporting enterprise monitoring and security operations. You will lead log onboarding initiatives, manage data ingestion pipelines, and ensure efficient indexing, searching, and reporting capabilities. The role requires expertise in Splunk infrastructure design, search head and indexer optimization, data model acceleration, and troubleshooting performance bottlenecks. You will work closely with security, infrastructure, and application teams to improve visibility across systems and support operational and cybersecurity objectives. This is an excellent opportunity to join a dynamic team supporting mission‑critical monitoring and SIEM environments.
Key Responsibilities
- Administer and maintain enterprise Splunk environments, ensuring high availability and performance
- Design and support Splunk architecture, including indexers, search heads, and forwarders
- Configure and optimize data onboarding, parsing, indexing, and ingestion workflows
- Monitor and tune Splunk platform performance to ensure scalability and reliability
- Create and manage knowledge objects including dashboards, reports, alerts, lookups, macros, and saved searches
- Develop and optimize field extractions, regex patterns, and data normalization processes
- Implement and maintain data models and data model acceleration
- Support SIEM operations through efficient log collection, event correlation, and reporting
- Troubleshoot indexing, search performance, and data ingestion issues
- Collaborate with security and operations teams to enhance monitoring and visibility capabilities
- Develop operational documentation, standards, and deployment procedures Required Qualifications & Skills
- Minimum 5+ years of hands‑on experience in Splunk Administration and Architecture
- Strong expertise in Splunk performance tuning and optimization
- Experience with log onboarding and data ingestion from multiple sources
- Hands‑on knowledge of Splunk Knowledge Object (KO) management
- Strong understanding of data models and acceleration techniques
- Experience creating and optimizing Splunk searches, dashboards, and reports
- Knowledge of indexer and search head architecture and optimization
- Expertise in Regex development and field extraction methodologies
- Strong troubleshooting and monitoring skills within Splunk environments
- Experience supporting SIEM log management and security monitoring use cases
- Strong analytical, documentation, and problem‑solving capabilities Nice‑to‑Have Skills
- Splunk Enterprise Security (ES) experience
- Experience integrating Splunk with SOAR platforms and threat intelligence solutions
- Knowledge of Linux and Windows system administration
- Familiarity with cloud platforms such as AWS, Azure, or Google Cloud
- Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Architect certifications Recruitment Pro Tip When applying for Splunk roles, showcase the scale of your environment—highlight the daily log volume managed, number of indexers/search heads administered, performance improvements delivered, and SIEM use cases implemented to demonstrate enterprise-level expertise.
Location:
Dubai United Arab Emirates.
Job Type
Full-Time. Application Method: Email CV to mano@mindpool-tech.com. Additional Info: Candidates able to join within 30 days or less are highly preferred; minimum 5+ years of experience required. Position Summary MindPool Technologies is seeking an experienced Splunk Administrator to manage, optimize, and support enterprise-scale Splunk environments. This role is critical in ensuring high-performance log management, security monitoring, data analytics, and SIEM operations across complex IT infrastructures. Detailed
Job Description
As a Splunk Administrator, you will be responsible for the architecture, administration, performance optimization, and ongoing management of Splunk platforms supporting enterprise monitoring and security operations. You will lead log onboarding initiatives, manage data ingestion pipelines, and ensure efficient indexing, searching, and reporting capabilities. The role requires expertise in Splunk infrastructure design, search head and indexer optimization, data model acceleration, and troubleshooting performance bottlenecks. You will work closely with security, infrastructure, and application teams to improve visibility across systems and support operational and cybersecurity objectives. This is an excellent opportunity to join a dynamic team supporting mission‑critical monitoring and SIEM environments.
Key Responsibilities
- Administer and maintain enterprise Splunk environments, ensuring high availability and performance
- Design and support Splunk architecture, including indexers, search heads, and forwarders
- Configure and optimize data onboarding, parsing, indexing, and ingestion workflows
- Monitor and tune Splunk platform performance to ensure scalability and reliability
- Create and manage knowledge objects including dashboards, reports, alerts, lookups, macros, and saved searches
- Develop and optimize field extractions, regex patterns, and data normalization processes
- Implement and maintain data models and data model acceleration
- Support SIEM operations through efficient log collection, event correlation, and reporting
- Troubleshoot indexing, search performance, and data ingestion issues
- Collaborate with security and operations teams to enhance monitoring and visibility capabilities
- Develop operational documentation, standards, and deployment procedures Required Qualifications & Skills
- Minimum 5+ years of hands‑on experience in Splunk Administration and Architecture
- Strong expertise in Splunk performance tuning and optimization
- Experience with log onboarding and data ingestion from multiple sources
- Hands‑on knowledge of Splunk Knowledge Object (KO) management
- Strong understanding of data models and acceleration techniques
- Experience creating and optimizing Splunk searches, dashboards, and reports
- Knowledge of indexer and search head architecture and optimization
- Expertise in Regex development and field extraction methodologies
- Strong troubleshooting and monitoring skills within Splunk environments
- Experience supporting SIEM log management and security monitoring use cases
- Strong analytical, documentation, and problem‑solving capabilities Nice‑to‑Have Skills
- Splunk Enterprise Security (ES) experience
- Experience integrating Splunk with SOAR platforms and threat intelligence solutions
- Knowledge of Linux and Windows system administration
- Familiarity with cloud platforms such as AWS, Azure, or Google Cloud
- Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Architect certifications Recruitment Pro Tip When applying for Splunk roles, showcase the scale of your environment—highlight the daily log volume managed, number of indexers/search heads administered, performance improvements delivered, and SIEM use cases implemented to demonstrate enterprise-level expertise.