Senior Splunk Administrator
WFA Digital Insight
Veeam’s Splunk team sits at the intersection of infrastructure, security and AI‑driven operations, making the senior administrator role uniquely technical and collaborative. The position calls for ownership of both on‑premises and Splunk Cloud environments, which means you’ll shape ingestion pipelines that span data centers, public clouds and SaaS services. Daily work blends performance tuning, storage efficiency and compliance support with close partnership across networking, application and audit groups. Candidates who thrive in fast‑moving, cross‑functional settings and can translate massive machine‑generated logs into clear operational insight will feel at home. Expect a culture that values continuous learning, hands‑on problem solving and a remote‑first mindset.
Job Description
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.
#LI-REMOTE #LI-JC2
About the Role
We are looking for a Senior Splunk Engineer to own and evolve Veeam’s Splunk environment across both on-premises and Splunk Cloud. This role will manage platform health, data ingestion, search performance, storage efficiency, dashboards, alerts, compliance support, and integrations across a broad enterprise environment.
The ideal candidate enjoys working at the center of infrastructure, security, cloud, monitoring, automation, and operational data, and can partner with infrastructure, cloud, security, application, audit, and service management teams. This is a high-impact role for someone who enjoys turning complex machine data into reliable operational insight.
What You’ll Do
- Manage, maintain, and improve Veeam’s Splunk Enterprise and Splunk Cloud environments.
- Design and support scalable log ingestion patterns across infrastructure, cloud platforms, applications, SaaS tools, security systems, and business services.
- Monitor and improve platform health, search performance, index utilization, storage efficiency, retention, data quality, and overall reliability.
- Partner with infrastructure, cloud, security, networking, application, audit, and service management teams to deliver trusted logging and observability capabilities.
- Build and maintain dashboards, alerts, reports, saved searches, field extractions, lookups, and knowledge objects that help teams identify and resolve issues faster.
- Lead data onboarding efforts, including source validation, parsing, sourcetype strategy, index design, field extraction, CIM alignment, HEC integrations, and forwarder configuration.
- Troubleshoot complex issues across Splunk architecture, operating systems, network paths, certificates, proxies, cloud services, and data pipelines.
- Support security, compliance, audit, and operational reporting use cases where accurate and searchable log data is critical.
- Define, document, and improve Splunk standards, runbooks, support procedures, onboarding patterns, and platform best practices.
Technologies You’ll Work With
- Splunk Enterprise
- Splunk Cloud
- Splunk Search Processing Language (SPL)
- Splunk Universal Forwarders, Heavy Forwarders, Deployment Server, Search Heads, Indexers
- Splunk HTTP Event Collector (HEC)
- Splunk apps, add-ons, dashboards, alerts, reports, lookups, data models, macros, tags, event types, and field extractions
- Windows and Linux server environments
- Azure, Azure Event Hub, Azure Monitor, Log Analytics, and cloud-native logging patterns
- REST APIs, webhooks, and automation frameworks
- PowerShell, Python, Bash, or similar scripting languages
- ServiceNow, Jira, or similar IT service management and work-tracking tools
- Observability, monitoring, security logging, compliance logging, and audit support workflows
What You’ll Bring
- Senior-level experience administering, engineering, or architecting Splunk in an enterprise environment.
- Hands-on experience with Splunk Enterprise, Splunk Cloud, or both.
- Strong understanding of Splunk architecture, including forwarders, indexers, search heads, deployment servers, apps, technical add-ons, indexes, sourcetypes, parsing, and retention.
- Experience onboarding data from multiple source types, including servers, network devices, cloud platforms, applications, SaaS tools, APIs, and security systems.
- Strong SPL skills, including the ability to create, troubleshoot, tune, and optimize searches, dashboards, reports, and alerts.
- Experience improving data quality, field extraction accuracy, search efficiency, storage usage, and platform stability.
- Strong troubleshooting skills across infrastructure, networking, operating systems, certificates, proxies, authentication, and distributed systems.
- Experience using scripting or APIs to automate repetitive tasks, reduce manual effort, and improve platform reliability.
- Ability to communicate clearly with technical and non-technical stakeholders.
Bonus Skills
- Splunk certifications such as Splunk Core Certified Power User, Advanced Power User, Enterprise Admin, Cloud Admin, Architect, or Consultant. Relevant security certifications are also desirable.
- Experience with Splunk Enterprise Security, Edge Processor, or search workload optimization.
- Experience supporting SOX, audit, compliance, security operations, or evidence collection use cases.
- Experience with Azure Event Hub, cloud-to-cloud data ingestion, HEC architecture, load balancing, and high availability patterns.
- Experience with CIM, data models, tstats, summary indexing, data quality governance, and dashboard optimization.
- Experience creating internal training, documentation, onboarding guides, or enablement materials for Splunk users.
How to Stand Out
- Highlight concrete examples of Splunk deployments you have built or optimized, especially any work that spans on‑prem and cloud environments.
- Include SPL queries or dashboard screenshots in your portfolio to demonstrate mastery of search language and visualization.
- Emphasize experience automating admin tasks with scripts or the Splunk REST API; interviewers often ask for a live coding demonstration.
- Prepare to discuss how you have balanced log retention policies with storage cost and compliance needs.
- Be ready to talk through a complex incident where log data helped resolve a production issue, focusing on your investigative process.
- When negotiating, reference the typical remote‑work stipend and equity components common for senior technical roles at high‑growth firms.
- Watch for vague promises about “flexible hours” without clear expectations on on‑call or overlap with core team time; clarify schedule expectations early.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.