1

Cribl Splunk Architect Jobs (NOW HIRING)

SIEM Data Engineer

Quincy, MA · On-site

$45 - $50/hr

Splunk certifications (e.g., Splunk Certified Architect or Splunk Certified Consultant). * CRIBL certifications (e.g., Cribl Certified Observability Engineer) * Experienced in administering Splunk ...

DevOps Engineer

Fort George G Meade, MD · On-site

$58.50 - $80.25/hr

Splunk * Cribl * NetFlow/sFlow * Syslog * Nagios * HP NNMi and HPNA * Support continuous ... Collaborate with Splunk Architects and System Administrators to improve platform resiliency and ...

At Cribl, we partner with IT and Security teams at many of the world's biggest enterprises ... Data Engineering/Analytics platform administrator/architect experience (i.e. Splunk, Elastic ...

At Cribl, we partner with IT and Security teams at many of the world's biggest enterprises ... Data Engineering/Analytics platform administrator/architect experience (i.e. Splunk, Elastic ...

At Cribl, we partner with IT and Security teams at many of the world's biggest enterprises ... Exceptional command over Big Data Analytics tools such as Splunk, Elastic, Grafana, DataDog ...

... Splunk Multi-Cluster Architecture; configuring, deploying, and maintaining the Cribl Log Stream platform; incident and Problem Management, Change and Release Management, Vendor Management, Capacity ...

As a Splunk and Cribl Engineer, you will prevent adversary network threats, identify advanced ... Knowledge of Zero Trust Architecture (ZTA) principles * Ability to automate security configurations ...

next page

Showing results 1-20

Cribl Splunk Architect information

See salary details

$58

$80

$91

How much do cribl splunk architect jobs pay per hour?

As of Jun 28, 2026, the average hourly pay for cribl splunk architect in the United States is $80.95, according to ZipRecruiter salary data. Most workers in this role earn between $74.76 and $88.46 per hour, depending on experience, location, and employer.

What are some common challenges faced by a Cribl Splunk Architect when integrating Cribl Stream with existing enterprise logging infrastructures?

A Cribl Splunk Architect often encounters challenges such as ensuring data compatibility between diverse log sources and Splunk, managing the performance impact of real-time data processing, and maintaining security compliance during data routing. Balancing the need for efficient data filtering and enrichment with minimal latency requires a deep understanding of both Cribl Stream and Splunk architectures. Close collaboration with IT, security, and DevOps teams is essential to address these challenges and to design scalable, resilient logging solutions that meet organizational requirements.

What other jobs could an architect do?

A Cribl Splunk Architect has skills in data management, system integration, and cloud environments, which can translate to roles such as Data Engineer, Systems Architect, or Cloud Solutions Architect. These positions often require knowledge of data pipelines, scripting, and infrastructure tools like AWS, Azure, or GCP. Certifications in data management or cloud platforms can enhance prospects for related roles.

What is the difference between Cribl Splunk Architect vs Splunk Engineer?

AspectCribl Splunk ArchitectSplunk Engineer
CertificationsCribl certifications, Splunk certificationsSplunk certifications, possibly Cribl certifications
Work EnvironmentDesigning data pipelines, architecture planningImplementing, configuring, and maintaining Splunk solutions
Industry UsageData pipeline architecture in IT and securitySplunk deployment and troubleshooting in similar sectors
Search & Comparison IntentFocus on architecture and data flow designFocus on operational deployment and support

The Cribl Splunk Architect primarily focuses on designing and implementing data pipelines using Cribl and Splunk architecture, while the Splunk Engineer concentrates on deploying, configuring, and maintaining Splunk solutions. Both roles require similar certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What does a Splunk architect do?

A Splunk architect designs, implements, and manages Splunk solutions for data analysis and security monitoring. They configure data ingestion, develop dashboards, and optimize system performance, often requiring knowledge of scripting, data modeling, and certifications like Splunk Certified Architect.

What is a Cribl Splunk Architect?

A Cribl Splunk Architect is a specialized IT professional responsible for designing, implementing, and optimizing data pipelines using Cribl Stream and integrating them with Splunk environments. They focus on managing large-scale log and event data, ensuring efficient data routing, transformation, and delivery to Splunk for analysis and monitoring. Their role involves architecting solutions that enhance observability, reduce data volumes, and improve performance across enterprise security and IT operations. Typically, they collaborate with security, DevOps, and IT teams to ensure seamless data flow and compliance with organizational requirements.

What are the key skills and qualifications needed to thrive as a Cribl Splunk Architect, and why are they important?

To excel as a Cribl Splunk Architect, you need expertise in log management, data engineering, and security information and event management (SIEM), typically backed by experience with Splunk and familiarity with Cribl's data routing solutions. Proficiency with tools like Splunk Enterprise, Cribl Stream, various log ingestion protocols, and relevant certifications such as Splunk Certified Architect are often required. Strong analytical thinking, problem-solving abilities, and effective communication skills help architects translate business requirements into technical solutions and guide teams through complex deployments. Mastering these skills ensures efficient data integration, optimized system performance, and robust security monitoring for organizations.

Is Cribl similar to Splunk?

Cribl and Splunk are related but serve different functions; Splunk is a data platform for indexing and analyzing machine data, while Cribl specializes in data routing, filtering, and transformation before it reaches platforms like Splunk. A Cribl Splunk Architect often works with both tools to optimize data workflows and integrations.

How much do Splunk architects make?

Splunk architects typically earn between $100,000 and $160,000 annually, depending on experience, certifications, and location. Senior roles with specialized skills in data analysis and system design can command higher salaries, especially in enterprise environments that rely heavily on Splunk for security and operational intelligence.
Infographic showing various Cribl Splunk Architect job openings in the United States as of June 2026, with employment types broken down into 68% Full Time, 1% Part Time, 2% Temporary, and 29% Contract. Highlights an 76% Physical, 5% Hybrid, and 19% Remote job distribution, with an average salary of $168,372 per year, or $80.9 per hour.

Cribl Engineer - Active TS/SCI

ENS Solutions, LLC

Washington, DC

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


Job description

Role Overview

We are seeking a highly experienced Cribl Engineer to serve as the principal technical authority for observability pipelines built on Cribl Stream and Cribl Edge. This role is designed for a senior technologist with deep expertise in log/telemetry routing, largescale data engineering, and enterprise-grade observability architectures.

You will shape pipeline strategy, design complex routing and transformation logic, drive platform reliability, mentor senior engineers, and serve as the top technical escalation point for Cribl-related challenges.

What You'll Do

  • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains.
  • Build high throughput pipelines (multiTB/day) with advanced routing, filtering, enrichment, and replay workflows.
  • Optimize system performance, worker topology, CPU/memory distribution, queues, and transport mechanisms.
  • Engineer secure data flows with masking, tokenization, RBAC, PKI/TLS, and other governance controls.
  • Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms, cloud services).
  • Develop HA/DR patterns, reliability frameworks, fleet health metrics, and failure mode response processes.
  • Maintain reusable Cribl packs, shared patterns, runbooks, and operational standards.
  • Serve as the senior escalation point for Cribl issues; interface with vendor engineering as required.
  • Mentor engineers, conduct design reviews, drive engineering excellence, and enforce architectural standards.
  • Support cross functional teams (security, cloud, analytics, infrastructure) on logging and telemetry strategy.

Requirements

  • 10+ years of experience in logging, observability, or SIEM engineering.
  • 5+ years architecting enterprise scale log/telemetry pipelines.
  • 3+ years handson with Cribl Stream and Cribl Edge in production environments.
  • Demonstrated success operating and scaling pipelines at 5-10+ TB/day.
  • Expert-level experience with Splunk forwarding/ingestion, source type management, and indexing practices.
  • Strong Linux fundamentals; scripting expertise (Python/Bash); Git; automation (Ansible/Terraform).
  • Strong understanding of transport protocols (HTTP, TCP, TLS/MTLS), Kafka, S3/object storage.
  • Experience designing secure data flows, including encryption, RBAC, secrets management, and compliance controls.
  • Demonstrated ability to mentor senior engineers and lead technical decision making.
  • Certified Cribl Certified Engineer (CCOE) or equivalent Cribl product expertise.
  • Must possess a TS/SCI; willingness to obtain a CI Poly
  • Must possess the following DoD 8570.01-M certifications or be willing to obtain within 30 days of hire:

o  Information Assurance Technician (IAT) Level II certification (currently Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND).

o  IAT Level III certification requirements (currently CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH).

o  Cyber Security Service Provider (CSSP) - Infrastructure Support (IS) certification requirements (currently CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND).

 Preferred Qualifications

  • Expertise creating and maintaining Cribl Packs and reusable pipelines.
  • Experience with cloud telemetry (AWS, Azure, hybrid) and crossdomain data movement patterns.
  • Familiarity with NIST / CIS control frameworks and secure engineering practices.
  • Experience building observability frameworks for large distributed systems.
  • Vendor engagement experience (Cribl PS, product teams, troubleshooting escalations).

Benefits

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?

  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS
  • 401k Contribution from Day 1
  • PTO + 11 Paid Federal Holidays
  • Long & Short Term Disability Insurance
  • Group Term Life Insurance
  • Tuition, Certification & Professional Development Assistance
  • Workers' Compensation
  • Relocation Assistance

Candidate AI Usage Policy

AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.