1

Splunk Administrator Jobs in Indiana (NOW HIRING)

LEAD ADMINISTRATOR L1

Chandler, IN · On-site

$60K - $135K/yr

LEAD ADMINISTRATOR L1 City: Chandler State/Province: Arizona Posting Start Date: 6/2/26 Wipro ... Dynatrace, Splunk) Secondary Skills: Scripting (Shell/Python/Perl), Batch Scheduling (Autosys ...

Tripwire Platform Engineer

Carmel, IN · On-site

$114K - $139K/yr

Administer, configure, and maintain Tripwire Enterprise components, including consoles, agents, policies, rules, and dashboards. * Integrate Tripwire with other systems such as ServiceNow and Splunk ...

Administer, configure, and maintain Tripwire Enterprise components, including consoles, agents, policies, rules, and dashboards. * Integrate Tripwire with other systems such as ServiceNow and Splunk ...

In the role, the HP NonStop (Tandem) System Administrator will be responsible for managing, maintaining, and optimizing mission-critical HP NonStop systems to ensure high availability, performance ...

In the role, the HP NonStop (Tandem) System Administrator will be responsible for managing, maintaining, and optimizing mission-critical HP NonStop systems to ensure high availability, performance ...

In the role, the HP NonStop (Tandem) System Administrator will be responsible for managing, maintaining, and optimizing mission-critical HP NonStop systems to ensure high availability, performance ...

Systems Administrator The Systems Administrator is responsible for providing administration and support for the business systems used by Ti Information Systems and develop a general understanding of ...

Systems Administrator The Systems Administrator is responsible for providing administration and support for the business systems used by Ti Information Systems and develop a general understanding of ...

Systems Administrator City: West Lafayette Job Summary Systems Administrator (Windows & Linux Environments) Purdue University / West Lafayette Indiana Join a collaborative, on-site team where your ...

next page

Showing results 1-20

Splunk Administrator information

What are the key skills and qualifications needed to thrive as a Splunk Administrator, and why are they important?

To thrive as a Splunk Administrator, you need strong knowledge of system administration, log management, and data analysis, typically supported by a bachelor’s degree in IT or related fields. Familiarity with Splunk Enterprise, SPL (Search Processing Language), and certifications like Splunk Certified Power User or Splunk Certified Admin are highly valued. Problem-solving ability, attention to detail, and effective communication are essential soft skills for success in this role. These competencies ensure reliable system performance, efficient data insights, and seamless collaboration with IT and security teams.

How much do Splunk admins make?

Splunk administrators typically earn a median annual salary ranging from $80,000 to $120,000, depending on experience, certifications, and location. Advanced skills in data analysis, scripting, and familiarity with Splunk tools can lead to higher compensation, especially in enterprise environments.

What is the difference between Splunk Administrator vs Security Information and Event Management (SIEM) Analyst?

AspectSplunk AdministratorSIEM Analyst
Required CertificationsSplunk Certified User, Splunk Core Certified Power UserGIAC Security Essentials, CompTIA Security+
Work EnvironmentIT teams managing Splunk deployments, data analysisSecurity teams monitoring security events, incident response
Employer & Industry UsageTech, finance, healthcare, any industry using SplunkCybersecurity firms, enterprise security departments

While both roles involve data analysis and security, a Splunk Administrator primarily manages and maintains Splunk platforms, ensuring data ingestion and system performance. In contrast, a SIEM Analyst focuses on analyzing security events, identifying threats, and responding to incidents using SIEM tools, including Splunk. Both roles often collaborate but serve different core functions within an organization's security and data infrastructure.

Who is Splunk's biggest competitor?

Splunk's main competitors include Elastic Stack (Elasticsearch, Logstash, Kibana), IBM QRadar, and LogRhythm, which also offer security information and event management (SIEM) and log management solutions. These companies compete for organizations seeking data analysis, monitoring, and security tools, often requiring knowledge of data indexing, search, and alerting features.

Is Splunk an EDR or SIEM?

Splunk is primarily a SIEM (Security Information and Event Management) platform used for security monitoring, log analysis, and threat detection. It can be extended with apps and add-ons to support EDR (Endpoint Detection and Response) functions, but its core role is as a SIEM tool. As a Splunk Administrator, understanding its SIEM capabilities is essential for managing security data and alerts.

What does a Splunk administrator do?

A Splunk administrator manages and maintains the Splunk platform, ensuring data is properly ingested, indexed, and accessible for analysis. They configure dashboards, set up alerts, troubleshoot issues, and optimize system performance, often requiring knowledge of scripting and security best practices.

What are some common challenges Splunk Administrators face when managing large-scale deployments?

Splunk Administrators often encounter challenges related to indexing large volumes of data, maintaining system performance, and ensuring data security across distributed environments. Managing data retention policies, optimizing search queries, and troubleshooting indexing or forwarding issues are routine tasks that require strong problem-solving skills. Collaboration with security, IT, and development teams is essential to ensure data sources are properly onboarded and dashboards meet organizational needs. Staying current with Splunk updates and best practices is also crucial for scalability and system reliability.

What are Splunk Administrators?

Splunk Administrators are IT professionals responsible for installing, configuring, managing, and maintaining Splunk environments. They ensure that Splunk software runs efficiently, managing data ingestion, indexing, and user access. Their role often includes troubleshooting issues, optimizing performance, and supporting users with dashboards and searches. Additionally, they may be involved in implementing security controls and integrating Splunk with other tools to enhance data analysis and reporting.
What are the most commonly searched types of Splunk Administrator jobs in Indiana? The most popular types of Splunk Administrator jobs in Indiana are:
What are popular job titles related to Splunk Administrator jobs in Indiana? For Splunk Administrator jobs in Indiana, the most frequently searched job titles are:
What job categories do people searching Splunk Administrator jobs in Indiana look for? The top searched job categories for Splunk Administrator jobs in Indiana are:
What cities in Indiana are hiring for Splunk Administrator jobs? Cities in Indiana with the most Splunk Administrator job openings:
Infographic showing various Splunk Administrator job openings in Indiana as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.
Splunk SIEM Engineer

Full-time

Medical, Retirement, PTO

Posted 13 days ago


Job description

Position Overview
Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.
We are seeking a skilled Splunk SIEM Engineer to lead the evolution of our Splunk environment into a fully operational, enterprise-grade Security Information and Event Management (SIEM) platform. This role will be responsible for both the build-out and ongoing operations of the platform, ensuring it delivers reliable, actionable security insights and supports evolving cybersecurity initiatives. This is a hybrid position that requires regular onsite presence in Crane, Indiana.
Key Responsibilities
  • Lead the transformation of the Splunk environment into a fully functional SIEM platform
  • Manage and optimize the data ingestion pipeline:
    • Audit existing data sources for relevance and efficiency
    • Eliminate unnecessary data ingestion to control licensing costs
    • Onboard and integrate new data sources
  • Parse, normalize, and map ingested data to the Splunk Common Information Model (CIM)
  • Configure, maintain, and optimize Splunk Enterprise Security (ES)
  • Configure, maintain, and optimize Splunk security orchestration, automation, and response platform (SOAR)
  • Develop and maintain correlation searches, detections, and use cases
  • Create and tune alerts to improve fidelity and reduce false positives
  • Build dashboards and visualizations for operational awareness and trend analysis
  • Monitor overall platform health and performance
  • Perform system upgrades, patching, and capacity planning
  • Manage intra Splunk certificates
  • Manage the lifecycle of security content:
    • Continuously refine detections and correlation rules
    • Enhance visibility and detection coverage based on emerging threats
  • Ensure consistent SIEM operations regardless of hosting environment or infrastructure ownership
  • Support ongoing security operations and future cybersecurity initiatives

Requirements
Required Qualifications
  • A SecurityX, CASP, or equivalent DoD 8140 IAT-3 certification is required.
  • Security Clearance: An interim DoD Secret security clearance or higher is required to start. Applicant selected may be subject to a security investigation and must meet eligibility requirements for access to classified information.
  • Hands-on experience with Splunk Enterprise and Splunk Enterprise Security (ES)
  • Strong understanding of SIEM architecture, design, and operations
  • Experience with log ingestion, parsing, normalization, and CIM mapping
  • Proficiency in developing correlation searches, alerts, and dashboards
  • Experience tuning SIEM content to reduce false positives and improve detection accuracy
  • Familiarity with data onboarding strategies and license optimization
  • Knowledge of cybersecurity principles, threat detection, and incident response
  • Experience with system administration tasks including patching, upgrades, and performance monitoring

Preferred Qualifications
  • Experience operating Splunk in distributed or multi-tenant environments
  • Knowledge of data pipelines and log forwarding technologies (e.g., syslog, APIs, forwarders)
  • Familiarity with frameworks such as MITRE ATT&CK
  • Experience supporting Zero Trust or advanced security architectures
  • Preferred certifications (e.g., Splunk Certified Admin, Splunk ES Certified, Security+)

Benefits
At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.
RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.
Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements.