emagine Polska is seeking a Senior Technical Lead Splunk to oversee and enhance Splunk and SIEM platforms within large enterprise environments. This role focuses on ensuring efficient operations, robust security posture, and the scalability of mission-critical monitoring systems.
Key responsibilities
- Support and administer Splunk/SIEM platforms, including log onboarding, source integration, and ingestion pipeline management.
- Deploy, configure, and optimize Splunk components, managing index lifecycles, retention policies, and storage.
- Optimize searches, dashboards, reports, and correlation searches to ensure high performance and scalability.
- Manage Splunk upgrades, patches, and release management while conducting security patching and vulnerability remediation.
- Perform root cause analysis and provide expert-level support for Splunk Enterprise and Splunk Enterprise Security.
Requirements
- 7-15 years of hands-on experience with Splunk/SIEM platforms in enterprise settings.
- Deep understanding of Splunk architecture, CIM onboarding, and performance optimization techniques.
- Minimum of two Splunk certifications, such as Splunk Core Certified Admin.
- Strong scripting and automation skills using Terraform and Ansible.
- Proven experience in administering Linux-based environments and managing platform migrations.
What we offer
- Opportunity to work in a complex, large-scale enterprise environment supporting Cyber Security and SOC operations.
- Full remote work environment with a focus on professional growth and technical leadership.
- Engagement in high-impact projects involving platform expansion and advanced security monitoring.