Brak wyników spełniających kryteria wyszukiwania.

About the Role
We are looking for an experienced Splunk Support Engineer (2nd Level Support) to join a team responsible for maintaining and developing a Splunk environment for a leading client in the financial sector.
If you enjoy solving complex technical challenges, ensuring platform stability, and collaborating with cross-functional teams, this opportunity is for you.
Key Responsibilities
Handle and resolve incidents and service requests related to the Splunk environment (P1–P4) in accordance with ITIL processes.
Diagnose and troubleshoot issues within Splunk architecture components, including:
Indexer Clusters
Search Head Clusters (SHC)
Deployment Servers
Universal and Heavy Forwarders
Monitor, analyze, and optimize platform performance, searches, dashboards, and scheduled searches.
Administer and maintain Splunk Enterprise and Splunk Cloud environments.
Manage users, roles, and permissions using RBAC principles.
Configure and maintain data sources, inputs, and indexing policies.
Support SOC operations and SIEM environments, including Splunk Enterprise Security (ES).
Participate in audits and support compliance and security-related activities.
Create and maintain technical documentation and operational procedures.
Collaborate with 1st and 3rd Level Support teams as well as vendor support.
Participate in upgrades, patch deployments, and change management processes.
Participate in on-call support rotations for critical systems.
Requirements
Minimum 3 years of experience administering and supporting Splunk platforms.
At least 1 year of experience in a 2nd Level Support or similar role.
Strong knowledge of Splunk architecture, including:
Indexer Clusters
Search Head Clusters (SHC)
Deployment Servers
Forwarders
Proven experience in troubleshooting and performance analysis of Splunk environments.
Strong knowledge of SPL (Search Processing Language) and reporting.
Experience administering Linux systems (RHEL, CentOS, Debian) and basic knowledge of Windows Server environments.
Good understanding of networking concepts, including TCP/IP, TLS/SSL, firewalls, and proxy servers.
Familiarity with ITIL processes and service management practices.
English language proficiency at C1 level.
German language is a strong plus
Splunk Core Certified Power User certification.
Nice to Have
Splunk Enterprise Certified Admin certification.
Experience with Splunk Enterprise Security (ES) and/or Splunk IT Service Intelligence (ITSI).
Knowledge of SOC processes, use case management, correlation rules, and Notable Events.
Experience working in the financial sector or other highly regulated environments.
Familiarity with regulatory frameworks such as DORA, BAIT, MaRisk, ISO 27001, and GDPR.
Knowledge of log sources commonly used in regulated environments (e.g., Active Directory, PAM, Core Banking Systems).
Experience with Kubernetes, Docker, AWS, Azure, or Splunk Cloud.
Scripting and automation skills using Python or Bash.
Experience with HEC (HTTP Event Collector), Syslog, and REST APIs.
ITIL 4 Foundation certification.
Additional certifications such as:
Splunk Enterprise Security Certified Admin
Splunk Certified Cybersecurity Defense Analyst
CompTIA Security+
Zainteresowany ofertą?
Aplikuj już teraz!