1

Cribl Splunk Architect Jobs (NOW HIRING)

Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains ... Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms ...

Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains ... Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms ...

Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains ... Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms ...

SIEM Architect/Engineer

New York, NY ยท On-site

$168K - $270K/yr

SIEM Architect / Engineer Location: New York, NY Base Salary Range: $168,924 - $270,278 Bring Your ... Utilize technologies such as Splunk, Cribl, Snowflake, Databricks, and AWS-native services to ...

SIEM Architect/Engineer

New York, NY ยท On-site

$168K - $270K/hr

SIEM Architect / Engineer Location: New York, NY Base Salary Range: $168,924 $270,278 Bring Your ... Utilize technologies such as Splunk, Cribl, Snowflake, Databricks, and AWS-native services to ...

next page

Showing results 1-20

Cribl Splunk Architect information

See salary details

$58

$80

$91

How much do cribl splunk architect jobs pay per hour?

As of Jun 29, 2026, the average hourly pay for cribl splunk architect in the United States is $80.95, according to ZipRecruiter salary data. Most workers in this role earn between $74.76 and $88.46 per hour, depending on experience, location, and employer.

What are some common challenges faced by a Cribl Splunk Architect when integrating Cribl Stream with existing enterprise logging infrastructures?

A Cribl Splunk Architect often encounters challenges such as ensuring data compatibility between diverse log sources and Splunk, managing the performance impact of real-time data processing, and maintaining security compliance during data routing. Balancing the need for efficient data filtering and enrichment with minimal latency requires a deep understanding of both Cribl Stream and Splunk architectures. Close collaboration with IT, security, and DevOps teams is essential to address these challenges and to design scalable, resilient logging solutions that meet organizational requirements.

What other jobs could an architect do?

A Cribl Splunk Architect has skills in data management, system integration, and cloud environments, which can translate to roles such as Data Engineer, Systems Architect, or Cloud Solutions Architect. These positions often require knowledge of data pipelines, scripting, and infrastructure tools like AWS, Azure, or GCP. Certifications in data management or cloud platforms can enhance prospects for related roles.

What is the difference between Cribl Splunk Architect vs Splunk Engineer?

AspectCribl Splunk ArchitectSplunk Engineer
CertificationsCribl certifications, Splunk certificationsSplunk certifications, possibly Cribl certifications
Work EnvironmentDesigning data pipelines, architecture planningImplementing, configuring, and maintaining Splunk solutions
Industry UsageData pipeline architecture in IT and securitySplunk deployment and troubleshooting in similar sectors
Search & Comparison IntentFocus on architecture and data flow designFocus on operational deployment and support

The Cribl Splunk Architect primarily focuses on designing and implementing data pipelines using Cribl and Splunk architecture, while the Splunk Engineer concentrates on deploying, configuring, and maintaining Splunk solutions. Both roles require similar certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What does a Splunk architect do?

A Splunk architect designs, implements, and manages Splunk solutions for data analysis and security monitoring. They configure data ingestion, develop dashboards, and optimize system performance, often requiring knowledge of scripting, data modeling, and certifications like Splunk Certified Architect.

What is a Cribl Splunk Architect?

A Cribl Splunk Architect is a specialized IT professional responsible for designing, implementing, and optimizing data pipelines using Cribl Stream and integrating them with Splunk environments. They focus on managing large-scale log and event data, ensuring efficient data routing, transformation, and delivery to Splunk for analysis and monitoring. Their role involves architecting solutions that enhance observability, reduce data volumes, and improve performance across enterprise security and IT operations. Typically, they collaborate with security, DevOps, and IT teams to ensure seamless data flow and compliance with organizational requirements.

What are the key skills and qualifications needed to thrive as a Cribl Splunk Architect, and why are they important?

To excel as a Cribl Splunk Architect, you need expertise in log management, data engineering, and security information and event management (SIEM), typically backed by experience with Splunk and familiarity with Cribl's data routing solutions. Proficiency with tools like Splunk Enterprise, Cribl Stream, various log ingestion protocols, and relevant certifications such as Splunk Certified Architect are often required. Strong analytical thinking, problem-solving abilities, and effective communication skills help architects translate business requirements into technical solutions and guide teams through complex deployments. Mastering these skills ensures efficient data integration, optimized system performance, and robust security monitoring for organizations.

Is Cribl similar to Splunk?

Cribl and Splunk are related but serve different functions; Splunk is a data platform for indexing and analyzing machine data, while Cribl specializes in data routing, filtering, and transformation before it reaches platforms like Splunk. A Cribl Splunk Architect often works with both tools to optimize data workflows and integrations.

How much do Splunk architects make?

Splunk architects typically earn between $100,000 and $160,000 annually, depending on experience, certifications, and location. Senior roles with specialized skills in data analysis and system design can command higher salaries, especially in enterprise environments that rely heavily on Splunk for security and operational intelligence.
Infographic showing various Cribl Splunk Architect job openings in the United States as of June 2026, with employment types broken down into 68% Full Time, 1% Part Time, 2% Temporary, and 29% Contract. Highlights an 76% Physical, 5% Hybrid, and 19% Remote job distribution, with an average salary of $168,372 per year, or $80.9 per hour.
Cribl Engineer Expert

Cribl Engineer Expert

DAn Solutions

Washington, DC โ€ข On-site

Full-time

Posted 17 days ago


Key responsibilities

  • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains.

  • Build high throughput pipelines with advanced routing, filtering, enrichment, and replay workflows.

  • Serve as the senior escalation point for Cribl issues and interface with vendor engineering as required.


Job description

REQUIRES AN EXISTING/ACTIVE TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK, MUST WORK ON SITE
Job Description:
We are seeking a highly experienced Cribl Engineer to serve as the principal technical authority for observability pipelines built on Cribl Stream and Cribl Edge. This role is designed for a senior technologist with deep expertise in log/telemetry routing, largescale data engineering, and enterprise-grade observability architectures.
You will shape pipeline strategy, design complex routing and transformation logic, drive platform reliability, mentor senior engineers, and serve as the top technical escalation point for Cribl-related challenges.
What You'll Do
  • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains.
  • Build high throughput pipelines (multiTB/day) with advanced routing, filtering, enrichment, and replay workflows.
  • Optimize system performance, worker topology, CPU/memory distribution, queues, and transport mechanisms.
  • Engineer secure data flows with masking, tokenization, RBAC, PKI/TLS, and other governance controls.
  • Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms, cloud services).
  • Develop HA/DR patterns, reliability frameworks, fleet health metrics, and failure mode response processes.
  • Maintain reusable Cribl packs, shared patterns, runbooks, and operational standards.
  • Serve as the senior escalation point for Cribl issues; interface with vendor engineering as required.
  • Mentor engineers, conduct design reviews, drive engineering excellence, and enforce architectural standards.
  • Support cross functional teams (security, cloud, analytics, infrastructure) on logging and telemetry strategy.

Required Qualifications
  • 10+ years of experience in logging, observability, or SIEM engineering.
  • 5+ years architecting enterprise scale log/telemetry pipelines.
  • 3+ years hands-on with Cribl Stream and Cribl Edge in production environments.
  • Demonstrated success operating and scaling pipelines at 5-10+ TB/day.
  • Expert-level experience with Splunk forwarding/ingestion, source type management, and indexing practices.
  • Strong Linux fundamentals; scripting expertise (Python/Bash); Git; automation (Ansible/Terraform).
  • Strong understanding of transport protocols (HTTP, TCP, TLS/MTLS), Kafka, S3/object storage.
  • Experience designing secure data flows, including encryption, RBAC, secrets management, and compliance controls.
  • Demonstrated ability to mentor senior engineers and lead technical decision making.
  • Certified Cribl Certified Engineer (CCOE) or equivalent Cribl product expertise.
  • Must possess the following DoD 8570.01-M certifications or be willing to obtain within 30 days of hire:
    • Information Assurance Technician (IAT) Level II certification (currently Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND).
    • IAT Level III certification requirements (currently CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH).
    • Cyber Security Service Provider (CSSP) - Infrastructure Support (IS) certification requirements (currently CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND).
  • Must possess a TS/SCI with Polygraph

Preferred Qualifications
  • Expertise creating and maintaining Cribl Packs and reusable pipelines.
  • Experience with cloud telemetry (AWS, Azure, hybrid) and cross-domain data movement patterns.
  • Familiarity with NIST / CIS control frameworks and secure engineering practices.
  • Experience building observability frameworks for large distributed systems.
  • Vendor engagement experience (Cribl PS, product teams, troubleshooting escalations).