Перейти до вмісту
co.brick Talents

Splunk Support Engineer

co.brick Talents Усі вакансії
Gliwice
Діє до 28 вер 2026
2 місяці тому

Коротко

Splunk Support Engineer (2nd Level) needed in Gliwice. Handle incidents, troubleshoot Splunk architecture, monitor performance, manage users & data sources. Requires 3+ yrs Splunk admin, 1+ yr 2nd level support, Linux admin, networking, ITIL, C1 English. B2B/Employment contract.

Стислий виклад підготував ШІ на основі тексту оголошення.

About the RoleWe are looking for an experienced Splunk Support Engineer (2nd Level Support) to join a team responsible for maintaining and developing a Splunk environment for a leading client in the financial sector.

If you enjoy solving complex technical challenges, ensuring platform stability, and collaborating with cross-functional teams, this opportunity is for you.

Key Responsibilities

Handle and resolve incidents and service requests related to the Splunk environment (P1–P4) in accordance with ITIL processes.

Diagnose and troubleshoot issues within Splunk architecture components, including:

Indexer Clusters

Search Head Clusters (SHC)

Deployment Servers

Universal and Heavy Forwarders

Monitor, analyze, and optimize platform performance, searches, dashboards, and scheduled searches.

Administer and maintain Splunk Enterprise and Splunk Cloud environments.

Manage users, roles, and permissions using RBAC principles.

Configure and maintain data sources, inputs, and indexing policies.

Support SOC operations and SIEM environments, including Splunk Enterprise Security (ES).

Participate in audits and support compliance and security-related activities.

Create and maintain technical documentation and operational procedures.

Collaborate with 1st and 3rd Level Support teams as well as vendor support.

Participate in upgrades, patch deployments, and change management processes.

Participate in on-call support rotations for critical systems.

Requirements

Minimum 3 years of experience administering and supporting Splunk platforms.

At least 1 year of experience in a 2nd Level Support or similar role.

Strong knowledge of Splunk architecture, including:

Indexer Clusters

Search Head Clusters (SHC)

Deployment Servers

Forwarders

Proven experience in troubleshooting and performance analysis of Splunk environments.

Strong knowledge of SPL (Search Processing Language) and reporting.

Experience administering Linux systems (RHEL, CentOS, Debian) and basic knowledge of Windows Server environments.

Good understanding of networking concepts, including TCP/IP, TLS/SSL, firewalls, and proxy servers.

Familiarity with ITIL processes and service management practices.

English language proficiency at C1 level.

German language is a strong plus

Splunk Core Certified Power User certification.

Nice to Have

Splunk Enterprise Certified Admin certification.

Experience with Splunk Enterprise Security (ES) and/or Splunk IT Service Intelligence (ITSI).

Knowledge of SOC processes, use case management, correlation rules, and Notable Events.

Experience working in the financial sector or other highly regulated environments.

Familiarity with regulatory frameworks such as DORA, BAIT, MaRisk, ISO 27001, and GDPR.

Knowledge of log sources commonly used in regulated environments (e.g., Active Directory, PAM, Core Banking Systems).

Experience with Kubernetes, Docker, AWS, Azure, or Splunk Cloud.

Scripting and automation skills using Python or Bash.

Experience with HEC (HTTP Event Collector), Syslog, and REST APIs.

ITIL 4 Foundation certification.

Additional certifications such as:

Splunk Enterprise Security Certified Admin

Splunk Certified Cybersecurity Defense Analyst

CompTIA Security+

Опубліковано 2026-06-30
Джерело