View all jobs

SIEM Data Onboarding Engineer (Splunk)

  • Toronto, ON

<meta content="text/html; charset=us-ascii" /> <style scoped="scoped" type="text/css">a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; } </style> emergiTEL is hiring a Splunk Engineer for our client in the Professional Services industry. This is a Contract role.
Compensation: $67.79 - $84.74/hour
Location: Toronto, Ontario, Canada (Onsite/Remote, EST Time Zone)
Job Description
  • Lead end-to-end Splunk data onboarding, including requirements analysis, ingestion design, implementation, validation, optimization, and troubleshooting.
  • Onboard a wide range of data sources including application logs, servers, databases, network and security devices, syslog feeds, APIs, and cloud platforms.
  • Configure and troubleshoot Splunk ingestion and parsing using inputs.conf, outputs.conf, props.conf, transforms.conf, indexes.conf, HEC, and Universal/Heavy Forwarders.
  • Configure sourcetypes, indexes, timestamps, event parsing, filtering, routing, and field extractions while resolving data quality and ingestion issues.
  • Normalize and map security data to the Splunk Common Information Model (CIM), including field mappings, tags, event types, and data models.
  • Develop and enhance Splunk Enterprise Security (ES) use cases, correlation searches, detections, alerts, dashboards, reports, and SPL searches.
  • Optimize searches, detections, dashboards, and scheduled jobs to improve performance and reduce false positives.
  • Configure, maintain, monitor, and troubleshoot enterprise Splunk environments, including distributed and clustered architectures.
  • Monitor platform health, ingestion pipelines, indexing and search performance, resource utilization, and capacity.
  • Perform root cause analysis, performance tuning, and operational support.
  • Maintain technical documentation, onboarding procedures, configuration standards, and operational runbooks.
Qualifications
  • Extensive hands-on experience as a Splunk Engineer or Senior Splunk Engineer in enterprise-scale environments.
  • Strong expertise in Splunk data onboarding for complex and high-volume data sources.
  • Proven experience with Splunk Enterprise Security (ES) and security use case development.
  • In-depth knowledge of Splunk CIM, data normalization, field mapping, tags, event types, and data models.
  • Strong understanding of Splunk architecture, ingestion, indexing, forwarding, search, and distributed environments.
  • Practical experience with Splunk configuration files including props.conf, transforms.conf, inputs.conf, outputs.conf, and indexes.conf.
  • Advanced SPL development and optimization skills.
  • Experience with platform monitoring, troubleshooting, and performance tuning.
  • Knowledge of Linux/Unix, networking, APIs, regular expressions, and log formats.
  • Python or Shell scripting experience is considered an asset.
  • Excellent analytical, problem-solving, written, and verbal communication skills.
  • Splunk certifications such as Enterprise Certified Admin, Architect, or Enterprise Security certifications are preferred.

Vacancy Status
This is an active position currently open for hiring.
Use of Artificial Intelligence
No artificial intelligence (AI) is used in the screening or selection process. All applications are reviewed by our recruitment team.
Equal Opportunity
emergiTEL is committed to creating a diverse and inclusive workplace. We welcome applications from all qualified individuals regardless of background. Hiring decisions are based solely on skills, experience, and qualifications relevant to the role.