1

Lead Splunk Engineer Jobs (NOW HIRING)

We are seeking a Principal Splunk Engineer to lead the design, operation, and evolution of our large-scale Splunk Enterprise / Splunk Cloud deployment. The platform ingests multi-terabyte daily data ...

Observability Engineer - Splunk ITSI Specialist Location: Remote / Hybrid (Client-site travel as ... • Lead client workshops to define observability strategy and service modeling frameworks • ...

Observability Engineer - Splunk ITSI Specialist Location: Remote / Hybrid (Client-site travel as ... Lead client workshops to define observability strategy and service modeling frameworks Develop ...

Observability Engineer Splunk ITSI Specialist Location: Remote / Hybrid (Client-site travel as ... Lead client workshops to define observability strategy and service modeling frameworks Develop ...

Splunk Architect Lead

Reston, VA · On-site

$57.50 - $78.75/hr

Splunk Architect Lead Location: Reston, VA Clearance Level: Secret (TS Eligible) SUMMARY Agile ... JOB DUTIES AND RESPONSIBILITIES Lead the design, engineering, configuration, and optimization of ...

Splunk Architect Lead

Reston, VA · Hybrid

$57.50 - $78.75/hr

Splunk Architect Lead Location: Reston, VA Clearance Level: Secret (TS Eligible) SUMMARY Agile ... JOB DUTIES AND RESPONSIBILITIES Lead the design, engineering, configuration, and optimization of ...

Leader, Solutions Engineer - Splunk, East

New York, NY · On-site +1

$112.10K - $147.70K/yr

Your Impact Splunk is looking for a dynamic, results-driven Solution Engineering Leader to lead and ... Lead, coach, and mentor and foster a culture of technical excellence, customer focus, and ...

Leader, Solutions Engineer - Splunk, East

New York, NY · On-site +1

$112.10K - $147.70K/yr

Your Impact Splunk is looking for a dynamic, results-driven Solution Engineering Leader to lead and ... Lead, coach, and mentor and foster a culture of technical excellence, customer focus, and ...

The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration, content development, and performance optimization while collaborating closely with SOC analysts, threat ...

Your Impact As a Senior Splunk Engineer, you will lead the end-to-end migration of our on-premise Splunk Enterprise environment to Splunk Cloud, ensuring seamless transition with zero data loss and ...

Information Security Engineer

Fulton, MD · On-site

$137.70K - $183.60K/yr

Your Impact As a Senior Splunk Engineer, you will lead the end-to-end migration of our on-premise Splunk Enterprise environment to Splunk Cloud, ensuring seamless transition with zero data loss and ...

Information Security Engineer

Annapolis Junction, MD · On-site

$137.70K - $183.60K/yr

Your Impact As a Senior Splunk Engineer, you will lead the end-to-end migration of our on-premise Splunk Enterprise environment to Splunk Cloud, ensuring seamless transition with zero data loss and ...

We lead without a title, empowering others through a can-do attitude. We look forward to the goal ... The Delivery Engineer | Splunk, will provide technical expertise in providing guidance on levels of ...

next page

Showing results 1-20

Lead Splunk Engineer information

See salary details

$42.5K

$123.8K

$180.5K

How much do lead splunk engineer jobs pay per year?

As of Jun 3, 2026, the average yearly pay for lead splunk engineer in the United States is $123,784.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,500.00 and $135,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Lead Splunk Engineer, and why are they important?

To thrive as a Lead Splunk Engineer, you need expertise in Splunk administration, log analysis, and system integration, typically supported by a degree in computer science or a related field. Proficiency with Splunk Enterprise, SPL (Search Processing Language), and relevant certifications like Splunk Certified Architect are highly valued. Strong problem-solving abilities, leadership, and effective communication are essential soft skills for guiding teams and collaborating across departments. These skills and qualifications ensure efficient management of complex data environments, robust security monitoring, and successful implementation of Splunk solutions.

What are some common challenges faced by Lead Splunk Engineers in managing large-scale deployments?

Lead Splunk Engineers often encounter challenges such as optimizing system performance across distributed environments, ensuring data integrity and security, and scaling infrastructure to handle increasing log volume. They also need to balance the demands of multiple stakeholders, troubleshoot complex data ingestion issues, and implement automation to streamline operations. Collaboration with security, IT, and DevOps teams is essential to maintain a reliable and efficient Splunk environment.

What does a Lead Splunk Engineer do?

A Lead Splunk Engineer oversees the design, implementation, and maintenance of Splunk environments within an organization. They are responsible for developing data ingestion strategies, creating dashboards and alerts, and ensuring the security and performance of Splunk deployments. In addition to technical tasks, they often lead a team of engineers, provide guidance on best practices, and collaborate with other IT and security teams to derive actionable insights from machine data.

What is the difference between Lead Splunk Engineer vs Splunk Engineer?

AspectLead Splunk EngineerSplunk Engineer
CertificationsSplunk Certified Power User, Admin, or ArchitectSplunk Certified Power User or Admin
Work EnvironmentLeads projects, mentors team, manages architecturePerforms deployment, configuration, and troubleshooting
ResponsibilitiesDesigns solutions, oversees implementation, guides teamSupports Splunk deployment, develops dashboards, maintains system

The main difference between a Lead Splunk Engineer and a Splunk Engineer lies in their responsibilities and leadership roles. The Lead typically manages projects, guides teams, and designs architecture, while the Splunk Engineer focuses on technical deployment and support tasks. Both roles require similar certifications and work in environments that utilize Splunk for data analysis and security.

More about Lead Splunk Engineer jobs
What job categories do people searching Lead Splunk Engineer jobs look for? The top searched job categories for Lead Splunk Engineer jobs are:
Infographic showing various Lead Splunk Engineer job openings in the United States as of May 2026, with employment types broken down into 4% As Needed, 4% Full Time, 84% Part Time, 2% Temporary, and 6% Contract. Highlights an 84% Physical, 7% Hybrid, and 9% Remote job distribution, with an average salary of $123,784 per year, or $59.5 per hour.

$122K - $200K/yr

Full-time

PTO

Posted 10 days ago


Job description

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Role Overview:

We are seeking a Principal Splunk Engineer to lead the design, operation, and evolution of our large-scale Splunk Enterprise / Splunk Cloud deployment. The platform ingests multi-terabyte daily data volumes across security, infrastructure, and application domains and is a critical component of our SOC and threat-detection capabilities. The ideal candidate has deep expertise in Splunk architecture, large-scale data onboarding, performance optimization, SmartStore/Indexer Clustering, and security-focused use cases.

Key Responsibilities:

Platform Architecture & Operations:

  • Architect, operate, and optimize a distributed, large-scale Splunk environment (indexer clusters, search head clusters, cluster masters, deployment servers, IDM, ADFS/SAML integrations)
  • Lead capacity planning, index design, data retention strategies, and SmartStore lifecycle management
  • Maintain high availability, scaling, and resilience across multi-site deployments (including DR strategy)
  • Drive Splunk version upgrades, app updates, cluster maintenance, and platform hardening

Security Logging & SOC Enablement:

  • Collaborate with SOC, Incident Response, and Threat Hunting teams to ensure high-quality security log ingestion
  • Onboard and normalize logs from firewalls, EDR, identity platforms, cloud providers, network telemetry, and custom applications
  • Develop and optimize detection content: correlation searches, risk-based alerting, data models, macros, lookups, summaries
  • Ensure compliance with logging standards (MITRE ATT&CK mapping, CIS/SOC2/ISO27001 logging requirements)

Data Engineering & Observability:

  • Build and manage ingestion pipelines, parsing, field extractions, CIM compliance, HEC configurations, and forwarder architecture
  • Implement data lifecycle tiers, filtering strategies, routing, and ingestion controls to reduce cost and improve efficiency
  • Optimize search performance, knowledge objects, summary indexing, and acceleration strategies

Governance & Best Practices:

  • Establish Splunk development standards, dashboards, and naming conventions
  • Mentor junior engineers and act as a technical escalation point for the team
  • Maintain documentation, operational runbooks, and logging onboarding guidelines
  • Partner with Engineering, Cloud, SecOps, and App teams to drive company-wide observability maturity

Required Qualifications:

5+ years experience administering large Splunk Enterprise or Splunk Cloud environments

Strong hands-on knowledge of:

  • Indexer clustering, search head clustering
  • SmartStore / S3-compatible object store design
  • Universal/heavy forwarder architecture
  • Ingest actions, parsing, props/transforms
  • KVStore, RBAC, SAML, encryption

Deep experience with security log ingestion and SIEM use cases

Strong SPL expertise, including:

  • Search optimization
  • Summary indexing / data model acceleration
  • CIM mapping and field normalization

Experience with Linux systems engineering, scripting (Python/Bash), and automation frameworks (Ansible, Terraform, GitOps preferred)

Preferred Qualifications:

Splunk certifications (Core Consultant, Enterprise Admin, Enterprise Architect, ES Analyst/ES Admin, or equivalent)

Experience with:

  • Enterprise Security (ES)
  • SOAR (Phantom or comparable)
  • AWS/Azure/GCP cloud logging architectures

Familiarity with high-throughput message brokers (Kafka/FluentD/Cribl)

Background in cybersecurity engineering or threat detection

Skills:

  • Automation
  • Influence
  • Result Orientation
  • Stakeholder Management
  • Technical Strategy Development
  • Application Development
  • Architecture
  • Business Acumen
  • Risk Management
  • Solution Design
  • Agile Practices
  • Analytical Thinking
  • Collaboration
  • Data Management
  • Solution Delivery Process

Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Transparency details

US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101), US - NJ - Pennington - 1300 American Blvd - Hopewell Bldg 3 (NJ2130)Pay and benefits informationPay range$122,000.00 - $200,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.