PC

Splunk Engineer/Architect

Accepting applications

Piper Companies · Morrisville, NC

Full-Time Mid_senior SOC
Posted
21h ago
Category
Design
Experience
Mid_senior
Country
United States
Piper Companies is seeking a Splunk Engineer / Architect to support a leading organization in the cybersecurity and enterprise technology industry. The Splunk Engineer / Architect will play a critical role in designing, implementing, and optimizing enterprise-scale Splunk environments within a SOC, with a strong focus on backend engineering and architectural design rather than dashboarding or end-user analytics. The Splunk Engineer/Architect is a long term contract opportunity, requires an active Secret Clearance and requires you to work onsite 5 days per week in RTP, NC.

Responsibilities of the Splunk Engineer / Architect:

Design and deploy scalable, highly available Splunk architectures across on-prem, cloud, and hybrid environments.
Lead Splunk engineering efforts including installation, configuration, upgrades, and ongoing platform maintenance (indexers, search heads, forwarders, clustering).
Develop and execute data ingestion strategies, including onboarding, normalization, parsing, and performance optimization.
Establish governance, platform standards, and best practices to ensure long-term scalability and reliability.
Support SOC operations by building and tuning SIEM use cases, correlation searches, and alerts aligned with MITRE ATT&CK.
Collaborate with cybersecurity and infrastructure teams to enhance threat detection, monitoring, and incident response capabilities.

Requirements of the Splunk Engineer / Architect:

Active Secret Clearance required.
5+ years of hands-on Splunk Engineering/Architecture experience (backend focus, not dashboarding).
Strong expertise with Splunk Enterprise and Splunk Enterprise Security (ES) in large-scale environments.
Deep understanding of data ingestion, indexing, clustering (indexer/search head), and search optimization.
Experience supporting Splunk within a SOC and contributing to SIEM/security monitoring strategies.

Compensation for the Splunk Engineer / Architect:

$140,000-$180,000
Full Comprehensive Benefits: Health, Vision, Dental, PTO, Paid Holiday and Sick Leave if Required by Law.

Keywords: Splunk, Splunk Engineer, Splunk Architect, SIEM, Splunk Enterprise, Splunk ES, Security Operations Center, SOC, data ingestion, indexer clustering, search head clustering, MITRE ATT&CK, threat detection, logging strategy, monitoring, cybersecurity, backend Splunk engineering, RTP jobs, active secret clearance

This job opens for applications on 07/31/2026. Applications for this job will be accepted for at least 30 days from the posting date.

#ONSITE

Show more Show less