Role Overview
The role requires an experienced Splunk professional responsible for executing production-grade changes, maintaining system health, ensuring compliance-driven operations, and supporting day-to-day change and incident activities within a 24x7 support model.
Key Responsibilities
- Change Execution: Execute production-level change requests strictly following Splunk TechOps runbooks, compliance controls, and approval workflows in ServiceNow.
- Configuration Review: Review, validate, and implement Splunk configuration changes ensuring accuracy and minimum risk.
- Runbook Management: Develop, update, and maintain runbooks with rollback procedures, validation steps, and versioned documentation.
- Incident Support: Support incident investigations, assist in root cause analysis, and respond to escalations as required.
- Monitoring & Troubleshooting: Use Splunk search, dashboards, and alerts to identify issues and ensure system stability.
- Process Adherence: Follow change processes, second-person review protocols, governance gates, and compliance standards.
- Reporting & KPIs: Track and report KPIs, SLAs, and change execution metrics, and provide ad hoc reporting when required.
Role Requirements
- Proficient in Splunk architecture, queries, dashboards, and operational best practices.
- Experience with orchestration tools such as Puppet (preferred) or similar automation platforms.
- Working knowledge of AWS cloud environments and Linux/Windows operating systems.
- Hands-on experience with ServiceNow change workflows.
- Ability to handle compliance-driven operations and documentation updates.
- Open to working in a 24x7 support model.
Experience Required
- 3 to 6 years of experience in Splunk administration, engineering, or production support.
- Strong troubleshooting abilities using Splunk Search and related tools; ITSI exposure is optional.
- Experience operating within structured, compliance-based engagement models.
Preferred Certifications
- Splunk Core Certified Admin or Power User
- ITIL Foundation
- Puppet or Ansible certification (desirable)