1

Lead Splunk Engineer Jobs (NOW HIRING)

Establish engineering standards and best practices across index naming, Sourcetypes, CIM compliance, field extractions, knowledge objects, configuration management, change control, application ...

Lead Splunk / Dynatrace Engineer

Hartford, CT · On-site

$103K - $136K/yr

Lead Splunk / Dynatrace Engineer Location: Hartford, CT Duration: long term Job Summary: We are seeking a Lead Splunk/Dynatrace Engineer with deep technical expertise in observability, search ...

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

Senior Cybersecurity Engineer Splunk

Charlotte, NC · On-site

$111K - $153K/yr

This role will lead the architecture and operations of Splunk Enterprise environments , data ... Key Responsibilities Splunk Architecture & Engineering * Design, deploy, and manage enterprise ...

Splunk ITSI Lead SME Location: New York, NY Job Type: Contract Role Overview The Splunk ITSI Lead ... Provide SME guidance to engineering and operations teams Required Skills & Experience * 7+ years of ...

Role Name -Technical Lead Role Descriptions: 1. 10 year of IT with 5 years of hands-on experience in Splunk Observability Cloud. 2. Create and maintain custom Splunk searches| alerts and saved ...

Senior Splunk Engineer

Washington, DC · On-site

$118K - $162K/yr

Senior Splunk Engineer ID: 1000000053 Location: Washington,DC Clearance Level: Active Top Secret ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

Senior Splunk Engineer

Washington, DC · On-site

$129K - $177K/yr

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

Splunk Engineer

Plano, TX · On-site

$63.68 - $71.68/hr

Genesis10 is currently seeking a Splunk Engineer for a contract position with a Global Financial ... use cases Lead incident response, troubleshooting, root cause analysis (RCA), and service ...

Senior Splunk Engineer

Washington, DC · On-site

$129K - $177K/yr

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring ...

Senior Splunk Engineer

Tampa, FL · On-site

$160K - $175K/yr

We lead with technical expertise, but that is just the tip of the iceberg - the 'Why' matters. At ... Platinum Technologies is seeking a Senior Splunk Engineer to join our company. We are seeking a ...

We lead with technical expertise, but that is just the tip of the iceberg - the 'Why' matters. At ... You.   Platinum Technologies is seeking a Senior Splunk Engineer to join our company. We are ...

Senior Splunk Engineer

Tampa, FL · On-site

$160K - $175K/yr

We lead with technical expertise, but that is just the tip of the iceberg - the 'Why' matters. At ... Platinum Technologies is seeking a Senior Splunk Engineer to join our company. We are seeking a ...

Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security ...

Senior Splunk Engineer

Washington, DC · On-site

$129K - $177K/yr

Responsibilities : • Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud ... junior engineers and maintain thorough documentation of configurations, processes, and best ...

next page

Showing results 1-20

Lead Splunk Engineer information

See salary details

$42.5K

$123.8K

$180.5K

How much do lead splunk engineer jobs pay per year?

As of Aug 3, 2026, the average yearly pay for lead splunk engineer in the United States is $123,784.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,500.00 and $135,000.00 per year, depending on experience, location, and employer.

What does a Lead Splunk Engineer do?

A Lead Splunk Engineer oversees the design, implementation, and maintenance of Splunk environments within an organization. They are responsible for developing data ingestion strategies, creating dashboards and alerts, and ensuring the security and performance of Splunk deployments. In addition to technical tasks, they often lead a team of engineers, provide guidance on best practices, and collaborate with other IT and security teams to derive actionable insights from machine data.

What are some common challenges faced by Lead Splunk Engineers in managing large-scale deployments?

Lead Splunk Engineers often encounter challenges such as optimizing system performance across distributed environments, ensuring data integrity and security, and scaling infrastructure to handle increasing log volume. They also need to balance the demands of multiple stakeholders, troubleshoot complex data ingestion issues, and implement automation to streamline operations. Collaboration with security, IT, and DevOps teams is essential to maintain a reliable and efficient Splunk environment.

What are the key skills and qualifications needed to thrive as a Lead Splunk Engineer, and why are they important?

To thrive as a Lead Splunk Engineer, you need expertise in Splunk administration, log analysis, and system integration, typically supported by a degree in computer science or a related field. Proficiency with Splunk Enterprise, SPL (Search Processing Language), and relevant certifications like Splunk Certified Architect are highly valued. Strong problem-solving abilities, leadership, and effective communication are essential soft skills for guiding teams and collaborating across departments. These skills and qualifications ensure efficient management of complex data environments, robust security monitoring, and successful implementation of Splunk solutions.

What is the difference between Lead Splunk Engineer vs Splunk Engineer?

AspectLead Splunk EngineerSplunk Engineer
CertificationsSplunk Certified Power User, Admin, or ArchitectSplunk Certified Power User or Admin
Work EnvironmentLeads projects, mentors team, manages architecturePerforms deployment, configuration, and troubleshooting
ResponsibilitiesDesigns solutions, oversees implementation, guides teamSupports Splunk deployment, develops dashboards, maintains system

The main difference between a Lead Splunk Engineer and a Splunk Engineer lies in their responsibilities and leadership roles. The Lead typically manages projects, guides teams, and designs architecture, while the Splunk Engineer focuses on technical deployment and support tasks. Both roles require similar certifications and work in environments that utilize Splunk for data analysis and security.

More about Lead Splunk Engineer jobs
What job categories do people searching Lead Splunk Engineer jobs look for? The top searched job categories for Lead Splunk Engineer jobs are:
Infographic showing various Lead Splunk Engineer job openings in the United States as of July 2026, with employment types broken down into 96% Full Time, 1% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $123,784 per year, or $59.5 per hour.

Lead Splunk Architect

CYKOR

Annapolis, MD • On-site

Full-time

Posted 25 days ago


Job description

Description:

CyKor is a fast-growing Technology Solutions Provider to both federal and commercial clients. We attribute our continued growth to our core values, our professional team, and the valuable relationships with our clients. Our small and growing team fosters an environment in which each team member is respected, valued, and appreciated for their contributions.


The Lead Splunk Architect is responsible for defining, governing, and leading the architecture, implementation, optimization, and operational maturity of the enterprise Splunk platform supporting cybersecurity operations, threat detection, incident response, compliance, and enterprise observability.


ROLE & RESPONSIBILITIES


Splunk Architecture & Platform Strategy

  • Define and architect enterprise Splunk architecture supporting high availability, scalability, resilience, disaster recovery, and long-term growth
  • Design and oversee distributed Splunk environments including: Indexer Clusters, Search Head Clusters, Deployment Servers, Cluster Managers, Heavy Forwarders, Universal Forwarders, License Management, Splunk Cloud and Hybrid architectures
  • Develop technical roadmaps, modernization strategies, migration plans, and platform lifecycle recommendations
  • Evaluate current platform capabilities and recommend architectural improvements supporting SOC operations and enterprise cybersecurity initiatives

Technical Leadership

  • Serve as the technical lead for all Splunk engineering activities
  • Provide mentorship and technical direction to Splunk Engineers, Security Engineers, Detection Engineers, and SOC Analysts
  • Review architecture, engineering designs, implementation plans, dashboards, searches, integrations, and custom applications
  • Establish engineering standards and best practices across index naming, Sourcetypes, CIM compliance, field extractions, knowledge objects, configuration management, change control, application lifecycle management, role-based access control

Platform Engineering & Operations

  • Architect scalable and resilient Splunk infrastructure supporting enterprise data volumes
  • Lead platform optimization including Search performance, Index performance, Storage management, Retention policies, License utilization, Data lifecycle management, Search concurrency, Data Model Acceleration
  • Guide upgrades, patching, backup, disaster recovery, and high availability planning
  • Lead troubleshooting of complex ingestion, parsing, indexing, search, and performance issues

Data Engineering & Integration

  • Define enterprise data onboarding strategies across security, infrastructure, cloud, identity, endpoint, network, and application data sources
  • Oversee parsing, routing, index design, field extraction, source normalization, CIM implementation, retention policies, data quality
  • Lead integrations with firewalls, IDS/ IPS, EDR, NDR, Identity providers, Cloud platforms, Vulnerability management, Ticketing systems, SIEM and SOAR technologies, Threat Intelligence platforms

Security Operations Enablement

  • Architect Splunk capabilities supporting Threat Detection, Threat Hunting, Incident Response, Security Monitoring, Risk-Based Alerting, Compliance Reporting
  • Guide development of Correlation Searches, Dashboards, Reports, Data Models, Detection Content, Enterprise Security Content
  • Improve detection fidelity while reducing false positives
  • Ensure Splunk capabilities support rapid investigation, evidence collection, event reconstruction, and executive reporting

Splunk SOAR & Automation

  • Architect automation strategies using Splunk SOAR
  • Design and oversee playbooks for Incident enrichment, IOC validation, Threat intelligence lookups, Malware analysis, Case management, Automated containment, Notification workflows
  • Integrate SOAR with enterprise security technologies using Python, REST APIs, and supported applications
  • Establish automation governance and reusable orchestration standards

Governance & Quality Assurance

  • Establish engineering governance for Configuration Management, App Lifecycle, Knowledge Object Management, Detection Content, Source Onboarding, Dashboard Standards
  • Review deployment packages and engineering deliverables prior to production release
  • Ensure engineering activities comply with change management, testing, documentation, rollback, and operational readiness requirements

Stakeholder Engagement

  • Serve as the primary technical advisor for Splunk architecture and platform strategy
  • Communicate technical risks, roadmap priorities, and architectural recommendations to executive leadership and program stakeholders
  • Translate business and mission requirements into scalable technical solutions
  • Coordinate activities with infrastructure, cloud, networking, identity, cybersecurity, and vendor teams

Documentation & Continuous Improvement

  • Develop and maintain Architecture diagrams, Engineering standards, Technical designs, Runbooks, Standard Operating Procedures, Disaster Recovery documentation, Knowledge Base articles, Technical decision records
  • Evaluate emerging Splunk capabilities and recommend improvements to maximize platform value
  • Foster engineering excellence through mentorship, standards, and continuous process improvement


Requirements:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field; equivalent professional experience may be substituted.
  • 8+ years of enterprise Splunk administration and engineering experience
  • 5+ years designing enterprise-scale distributed Splunk environments
  • Experience leading Splunk Enterprise Security implementations
  • Experience with Splunk Cloud and hybrid architectures
  • Experience supporting Security Operations Centers (SOC)
  • Experience leading technical teams and architecture initiatives
  • Experience with enterprise cybersecurity monitoring and incident response
  • Active security clearance strongly preferred (Public Trust or higher)


CERTIFICATIONS:

Required: Splunk Enterprise Certified Architect

Preferred: Splunk Enterprise Security Certified Admin; Splunk Core Certified Consultant; Splunk SOAR Certified Automation Developer; CISSP; GIAC (GCIA, GCIH, or GCED); AWS, Azure, or Google Cloud certifications


LOCATION AND TRAVEL:

  • Remote schedule with availability for some related travel (0%-25%)