1

Splunk Architect Jobs in Baltimore, MD (NOW HIRING)

The Lead Splunk Architect is responsible for defining, governing, and leading the architecture, implementation, optimization, and operational maturity of the enterprise Splunk platform supporting ...

... SPLUNK Architecture certification. • Knowledge of cloud computing platforms • Scripting and coding experience a plus • Must have at least one Information Security related certification ...

CyberLinx Solutions, LLC is seeking for a Splunk Architect.Candidate must have a Security Clearance(WP). Systems engineers will be requested to participate in the process by which a new software ...

Splunk Engineer 4

Laurel, MD · On-site

$249K - $266K/yr

Architect, implement, and manage Splunk infrastructure and solutions. * Administer Splunk Enterprise security. * Develop and deploy complex Splunk searches. * Administer search head clusters, indexer ...

Architect, implement, and manage Splunk infrastructure and solutions. * Administer Splunk Enterprise security. * Develop and deploy complex Splunk searches. * Administer search head clusters, indexer ...

next page

Showing results 1-20

Splunk Architect information

See Baltimore, MD salary details

$58

$80

$90

How much do splunk architect jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for splunk architect in Baltimore, MD is $80.43, according to ZipRecruiter salary data. Most workers in this role earn between $74.28 and $87.88 per hour, depending on experience, location, and employer.

What is the difference between Splunk Architect vs Splunk Engineer?

AspectSplunk ArchitectSplunk Engineer
Primary RoleDesigns and oversees the overall Splunk deployment architectureDevelops, implements, and maintains Splunk solutions and dashboards
Required SkillsArchitecture design, project management, advanced Splunk knowledgeSplunk configuration, scripting, data ingestion, troubleshooting
CertificationsSplunk Certified Architect, Splunk Certified Power UserSplunk Certified Power User, Splunk Certified Admin
Work EnvironmentTypically in enterprise IT teams, focusing on planning and architectureHands-on technical roles within IT or security teams

Splunk Architects focus on designing and planning the overall Splunk infrastructure, ensuring scalability and integration, while Splunk Engineers handle the day-to-day implementation, configuration, and troubleshooting of Splunk solutions. Both roles require strong Splunk certifications and technical expertise, but differ mainly in scope and responsibilities.

What is a Splunk Architect?

As a Splunk architect, you create applications that can perform specific tasks within the Splunk environment. Your responsibilities may include application or software development supporting customized data solutions for your employer or client. For example, you may create a dashboard on which you can select and visualize information from a database, then use that data to generate a report. As a Splunk architect, you may also be responsible for the security of the system and network that the company uses to operate Splunk solutions.

What is a Splunk Architect?

A Splunk Architect is an IT professional who designs, configures, and optimizes Splunk environments for organizations. They are responsible for creating scalable architectures, ensuring data is efficiently ingested and searchable, and setting up dashboards and alerts for monitoring and analysis. Splunk Architects work closely with security, IT, and business teams to tailor the platform to organizational needs and ensure best practices in deployment and data management. Their expertise ensures that Splunk solutions are robust, secure, and aligned with business objectives.

What are the key skills and qualifications needed to thrive as a Splunk Architect, and why are they important?

To thrive as a Splunk Architect, you need expertise in Splunk deployment, data ingestion, and security information and event management (SIEM), often supported by a bachelor’s degree in computer science or a related field. Familiarity with Splunk Enterprise, Splunk Cloud, scripting languages (like Python), and certifications such as Splunk Certified Architect are typically required. Strong analytical thinking, problem-solving skills, and the ability to communicate complex technical concepts clearly are crucial soft skills. These skills ensure the effective design, implementation, and optimization of Splunk solutions that meet organizational security and operational needs.

How does a Splunk Architect collaborate with other IT teams to ensure effective data integration and system performance?

A Splunk Architect regularly works with security, operations, and development teams to design and implement data ingestion pipelines, define data models, and optimize search performance. They often lead technical workshops to understand data sources and application requirements, ensuring that Splunk environments are tailored to organizational needs. Effective collaboration includes setting data governance standards, troubleshooting integration issues, and mentoring team members on best practices for using Splunk. This cross-functional teamwork helps maintain secure, scalable, and high-performing analytics platforms.

What job categories do people searching Splunk Architect jobs in Baltimore, MD look for?

The top searched job categories for Splunk Architect jobs in Baltimore, MD are:

Infographic showing various Splunk Architect job openings in Baltimore, MD as of August 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 82% In-person, and 18% Remote job distribution, with an average salary of $167,294 per year, or $80.4 per hour.

Lead Splunk Architect

CYKOR

Annapolis, MD • On-site

Full-time

Re-posted 8 days ago


Job description

Description:

CyKor is a fast-growing Technology Solutions Provider to both federal and commercial clients. We attribute our continued growth to our core values, our professional team, and the valuable relationships with our clients. Our small and growing team fosters an environment in which each team member is respected, valued, and appreciated for their contributions.


The Lead Splunk Architect is responsible for defining, governing, and leading the architecture, implementation, optimization, and operational maturity of the enterprise Splunk platform supporting cybersecurity operations, threat detection, incident response, compliance, and enterprise observability.


ROLE & RESPONSIBILITIES


Splunk Architecture & Platform Strategy

  • Define and architect enterprise Splunk architecture supporting high availability, scalability, resilience, disaster recovery, and long-term growth
  • Design and oversee distributed Splunk environments including: Indexer Clusters, Search Head Clusters, Deployment Servers, Cluster Managers, Heavy Forwarders, Universal Forwarders, License Management, Splunk Cloud and Hybrid architectures
  • Develop technical roadmaps, modernization strategies, migration plans, and platform lifecycle recommendations
  • Evaluate current platform capabilities and recommend architectural improvements supporting SOC operations and enterprise cybersecurity initiatives

Technical Leadership

  • Serve as the technical lead for all Splunk engineering activities
  • Provide mentorship and technical direction to Splunk Engineers, Security Engineers, Detection Engineers, and SOC Analysts
  • Review architecture, engineering designs, implementation plans, dashboards, searches, integrations, and custom applications
  • Establish engineering standards and best practices across index naming, Sourcetypes, CIM compliance, field extractions, knowledge objects, configuration management, change control, application lifecycle management, role-based access control

Platform Engineering & Operations

  • Architect scalable and resilient Splunk infrastructure supporting enterprise data volumes
  • Lead platform optimization including Search performance, Index performance, Storage management, Retention policies, License utilization, Data lifecycle management, Search concurrency, Data Model Acceleration
  • Guide upgrades, patching, backup, disaster recovery, and high availability planning
  • Lead troubleshooting of complex ingestion, parsing, indexing, search, and performance issues

Data Engineering & Integration

  • Define enterprise data onboarding strategies across security, infrastructure, cloud, identity, endpoint, network, and application data sources
  • Oversee parsing, routing, index design, field extraction, source normalization, CIM implementation, retention policies, data quality
  • Lead integrations with firewalls, IDS/ IPS, EDR, NDR, Identity providers, Cloud platforms, Vulnerability management, Ticketing systems, SIEM and SOAR technologies, Threat Intelligence platforms

Security Operations Enablement

  • Architect Splunk capabilities supporting Threat Detection, Threat Hunting, Incident Response, Security Monitoring, Risk-Based Alerting, Compliance Reporting
  • Guide development of Correlation Searches, Dashboards, Reports, Data Models, Detection Content, Enterprise Security Content
  • Improve detection fidelity while reducing false positives
  • Ensure Splunk capabilities support rapid investigation, evidence collection, event reconstruction, and executive reporting

Splunk SOAR & Automation

  • Architect automation strategies using Splunk SOAR
  • Design and oversee playbooks for Incident enrichment, IOC validation, Threat intelligence lookups, Malware analysis, Case management, Automated containment, Notification workflows
  • Integrate SOAR with enterprise security technologies using Python, REST APIs, and supported applications
  • Establish automation governance and reusable orchestration standards

Governance & Quality Assurance

  • Establish engineering governance for Configuration Management, App Lifecycle, Knowledge Object Management, Detection Content, Source Onboarding, Dashboard Standards
  • Review deployment packages and engineering deliverables prior to production release
  • Ensure engineering activities comply with change management, testing, documentation, rollback, and operational readiness requirements

Stakeholder Engagement

  • Serve as the primary technical advisor for Splunk architecture and platform strategy
  • Communicate technical risks, roadmap priorities, and architectural recommendations to executive leadership and program stakeholders
  • Translate business and mission requirements into scalable technical solutions
  • Coordinate activities with infrastructure, cloud, networking, identity, cybersecurity, and vendor teams

Documentation & Continuous Improvement

  • Develop and maintain Architecture diagrams, Engineering standards, Technical designs, Runbooks, Standard Operating Procedures, Disaster Recovery documentation, Knowledge Base articles, Technical decision records
  • Evaluate emerging Splunk capabilities and recommend improvements to maximize platform value
  • Foster engineering excellence through mentorship, standards, and continuous process improvement


Requirements:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field; equivalent professional experience may be substituted.
  • 8+ years of enterprise Splunk administration and engineering experience
  • 5+ years designing enterprise-scale distributed Splunk environments
  • Experience leading Splunk Enterprise Security implementations
  • Experience with Splunk Cloud and hybrid architectures
  • Experience supporting Security Operations Centers (SOC)
  • Experience leading technical teams and architecture initiatives
  • Experience with enterprise cybersecurity monitoring and incident response
  • Active security clearance strongly preferred (Public Trust or higher)


CERTIFICATIONS:

Required: Splunk Enterprise Certified Architect

Preferred: Splunk Enterprise Security Certified Admin; Splunk Core Certified Consultant; Splunk SOAR Certified Automation Developer; CISSP; GIAC (GCIA, GCIH, or GCED); AWS, Azure, or Google Cloud certifications


LOCATION AND TRAVEL:

  • Remote schedule with availability for some related travel (0%-25%)