Senior Splunk Engineer

The Intersect Group

Phoenix, AZ(remote)

JOB DETAILS
SKILLS
Analysis Skills, Applications Security, Business Case, CIM (Common Information Model), Centralized Operations/Management, Cloud Computing, Command Line, Communication Skills, Community and Social Services, Computer Security, Computer Skills, Contract Management, Data Modeling, Data Quality, Enterprise Protection, Firewalls, Forwarder, Identify Issues, Information Technology & Information Systems, Internet Security, JSON, Linux Operating System, Machine Tool, Onboarding, Operational Audit, Operational Improvement, Operations Security (OPSEC), Public Safety, Public Transport, Python Programming/Scripting Language, Reporting Dashboards, Scripting (Scripting Languages), Security Analysis, Software Engineering, Splunk, Technical Support, Use Cases, Windows PowerShell, XML (EXtensible Markup Language)
LOCATION
Phoenix, AZ
POSTED
30 days ago


Splunk Engineer / Administrator (Contract)
Location: Greater Phoenix Area preferred (open to fully remote candidates working Arizona hours)
Engagement: 12?month, full?time contract
Future opportunity: Strong potential for long?term extension or conversion to permanent employment
About the Opportunity
This role supports a large, enterprise public?sector technology environment serving one of the fastest?growing metropolitan regions in the U.S. The organization is widely recognized for its investment in data?driven decision making, smart infrastructure, cybersecurity modernization, and cloud?first platforms.
Technology teams operate at scale, supporting critical services such as public safety, transportation, utilities, and community services. There is a sustained focus on modern analytics, centralized monitoring, and operational resilience, providing engineers with the opportunity to work on complex, high?impact systems that directly affect millions of residents.
This position offers the stability of a public?sector environment combined with modern tooling, long?term planning, and meaningful real?world impact.
Role Overview
The Splunk Engineer will support and enhance an enterprise Splunk Cloud environment by onboarding new systems and data sources, developing dashboards and alerts, and delivering analytics that improve operational visibility, security posture, and service reliability.
This is a highly technical, hands?on role requiring strong experience with Splunk administration, data onboarding, and SPL development, along with close collaboration across infrastructure, application, and security teams.
Key Responsibilities
  • Onboard new systems, logs, and data sources into Splunk, ensuring proper parsing, field extractions, CIM compliance, and data normalization
  • Configure and maintain Splunk forwarders, ingestion pipelines, and data routing
  • Build advanced dashboards, visualizations, and analytics for operational, security, and business use cases
  • Develop complex SPL queries, macros, lookups, and scheduled searches
  • Troubleshoot ingestion issues, search performance challenges, and data quality problems
  • Partner with network, server, application, and security teams to define log requirements and actionable monitoring

Minimum Qualifications
  • Experience administering and engineering Splunk Enterprise or Splunk Cloud in medium?to?large environments
  • Strong proficiency with SPL for analytics and troubleshooting
  • Demonstrated experience onboarding new systems or applications into Splunk
  • Experience building dashboards using Splunk Dashboard Studio or the Classic Editor
  • Knowledge of common log ingestion formats such as syslog, JSON, and XML, including data parsing and field extraction
  • Solid understanding of IT infrastructure fundamentals, including servers, networks, firewalls, and cloud services
  • Experience working with Linux command line tools and managing Splunk Universal and Heavy Forwarders

Preferred Qualifications
  • Experience with automation or scripting using Python or PowerShell
  • Experience with Splunk Enterprise Security and/or IT Service Intelligence
  • Familiarity with distributed Splunk architectures, including indexer clustering and search head clustering
  • Experience implementing CIM compliance and working with Splunk data models

Ideal Candidate Profile
  • Strong analytical and troubleshooting skills with the ability to create clear, effective visualizations
  • Comfortable collaborating with infrastructure, application, and security teams in a large enterprise environment
  • Strong communication skills with the ability to translate technical findings into actionable insights

Why This Role
  • Work on enterprise?scale Splunk Cloud and monitoring platforms supporting critical, high?visibility services
  • Contribute to long?term modernization, security, and operational excellence initiatives
  • Stable, full?time contract with clear potential for extension or permanent conversion
  • Flexible work model with openness to remote candidates aligned to Arizona work hours
  • Opportunity to make a tangible impact through technology that supports essential community services

About the Company

T

The Intersect Group

The Intersect Group is a different and better business partner. We create unparalleled value for our clients by combining industry-leading Consulting capabilities with comprehensive Staffing and recruitment services. Clients trust us to deliver results based on our deep expertise and proven resources within finance, accounting, and information technology. Through our flexible delivery approach, you get the right solution, at the right time to accelerate your success and achieve all of your mission-critical objectives.

COMPANY SIZE
500 to 999 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2006