Splunk Architect Lead

ECS Federal LLC

DC

JOB DETAILS
SKILLS
Access Control, Analysis Skills, Application Integration, Applications Security, Architectural Services, Automation, Best Practices, CIM (Common Information Model), Case Management, Change Control, Change Management, Cloud Computing, Concurrency, Configuration Management, Continuous Improvement, DNS (Domain Name System), Data Management, Data Modeling, Data Quality, Data Recovery, Design Document, Disaster Recovery, Documentation, Documentation Standards, Engineering, Enterprise Protection, Establish Priorities, Firewalls, Forwarder, High Availability, Hunting, Hybrid Cloud, Identify Issues, Incident Response, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Knowledge Modeling, Leadership, Licensing, Mentoring, Onboarding, Operational Support, Operations Processes, Operations Security (OPSEC), Performance Analysis, Performance Modeling, Performance Tuning/Optimization, Problem Solving Skills, Product Support, Product Testing, Production Systems, Quality Assurance, Regulatory Compliance, Reliability Engineering, Reporting Dashboards, Risk, Security Analysis, Security Infrastructure, Security Monitoring, Server Clusters, Software Development Lifecycle (SDLC), Software Patches, Splunk, Systems Administration/Management, Technical Leadership, Technical/Engineering Design, Testing, Time Management, Use Cases
LOCATION
DC
POSTED
30+ days ago

Everforth ECS is seeking a Splunk Architect Lead to work in our Portland, OR office. Please Note: This position is contingent upon contract award.

The Splunk Architect and Lead is responsible for defining, guiding, and overseeing the architecture, implementation, optimization, and governance of Splunk capabilities that support cybersecurity monitoring, threat detection, incident response, reporting, and enterprise security operations. This role provides technical leadership for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, and related integrations across complex operational environments.

The ideal candidate combines deep Splunk architecture expertise, hands-on engineering experience, security operations knowledge, and leadership ability to guide engineers, analysts, stakeholders, and vendors. This role establishes scalable designs, enforces technical standards, ensures platform reliability, and translates mission and SOC requirements into secure, maintainable, and operationally effective Splunk solutions.

Key Responsibilities

Splunk Architecture & Strategy

  • Define and maintain the target Splunk architecture, including indexer clusters, search head clusters, deployment servers, heavy forwarders, universal forwarders, apps, add-ons, integrations, storage, and high-availability components.
  • Develop technical roadmaps, architecture recommendations, implementation plans, and modernization strategies for Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, or hybrid Splunk environments.
  • Ensure Splunk architecture supports SOC operations, security monitoring, incident response, compliance reporting, data retention, scalability, resilience, and performance requirements.
  • Assess current-state capabilities, identify architectural gaps, and recommend improvements aligned to program priorities, operational needs, and cybersecurity best practices.

Technical Leadership & Governance

  • Serve as the technical lead for Splunk engineering activities, providing direction, review, and mentorship to Splunk engineers, security engineers, analysts, and other technical contributors.
  • Establish and enforce Splunk standards for index naming, sourcetypes, field extractions, Common Information Model alignment, knowledge objects, access controls, app deployment, configuration management, and change control.
  • Review major design decisions, configuration changes, content deployments, and integration approaches for technical soundness, maintainability, security, and operational impact.
  • Coordinate Splunk engineering priorities, assign technical work as needed, and ensure deliverables are completed accurately, consistently, and on schedule.

Platform Design, Scalability & Reliability

  • Lead design efforts for platform performance, capacity, storage, retention, data lifecycle management, search concurrency, licensing, disaster recovery, backup, and high availability.
  • Oversee platform health monitoring, performance tuning, system optimization, upgrade planning, patching strategies, and long-term maintenance planning.
  • Guide troubleshooting of complex issues involving ingestion delays, parsing problems, skipped or dropped data, search performance, data model acceleration, app conflicts, and infrastructure dependencies.
  • Partner with infrastructure, cloud, network, identity, endpoint, and system administration teams to ensure Splunk architecture integrates securely and reliably with the broader environment.

Data Architecture & Integration Oversight

  • Define data onboarding architecture and integration patterns for security, infrastructure, cloud, endpoint, network, identity, application, vulnerability, and operational data sources.
  • Oversee normalization, parsing, field extraction, data routing, index design, retention settings, source coverage, and Splunk Common Information Model implementation.
  • Prioritize data source onboarding based on mission value, SOC use cases, detection requirements, compliance needs, and platform capacity constraints.
  • Ensure integrations with EDR, NDR, firewalls, IDS/IPS, proxy, DNS, cloud platforms, identity providers, ticketing systems, SOAR platforms, and case management tools are secure, reliable, and supportable.

Security Analytics & SOC Enablement

  • Translate SOC, threat hunting, threat intelligence, incident response, and leadership requirements into Splunk architecture, data, dashboard, reporting, and detection engineering capabilities.
  • Provide technical guidance for correlation searches, notable event rules, dashboards, reports, risk-based alerting, data models, content packs, and security monitoring use cases.
  • Support detection tuning, alert fidelity improvement, false-positive reduction, source coverage analysis, and monitoring gap remediation in coordination with SOC leadership and analysts.
  • Ensure Splunk content and data capabilities support timely triage, investigation, evidence retrieval, event reconstruction, and operational reporting.

Implementation Oversight & Quality Assurance

  • Lead or oversee implementation activities for Splunk platform components, integrations, apps, add-ons, dashboards, reports, alerts, and security content.
  • Validate engineering work products, test plans, deployment packages, configuration changes, and operational procedures before release into production environments.
  • Ensure Splunk changes follow approved change management, configuration management, testing, documentation, and rollback processes.
  • Coordinate with vendors, product support, and external technical teams to resolve complex issues and evaluate new capabilities.

Stakeholder Engagement & Program Support

  • Act as the primary technical point of contact for Splunk architecture, platform strategy, implementation risks, technical dependencies, and capability planning.
  • Brief program leadership, SOC leadership, technical teams, and stakeholders on Splunk status, risks, roadmap items, architectural decisions, and recommended investments.
  • Translate complex Splunk platform issues, data coverage gaps, and technical tradeoffs into clear operational and business language.
  • Support planning, estimation, schedule coordination, status reporting, and prioritization for Splunk-related initiatives.

Documentation, Standards & Continuous Improvement

  • Develop and maintain architecture diagrams, engineering standards, design documents, runbooks, operational procedures, troubleshooting guides, and technical decision records.
  • Maintain governance for knowledge object management, role-based access, app lifecycle management, source onboarding, dashboard standards, and detection content lifecycle processes.
  • Evaluate emerging Splunk features, apps, add-ons, integrations, automation approaches, and security analytics practices to improve reliability, efficiency, and mission value.
  • Mentor technical staff and promote consistent Splunk engineering practices, SPL development standards, data quality expectations, and operational discipline.

About the Company

E

ECS Federal LLC

ECS was founded in 2001 by experienced IT professionals with a commitment to quality processes, people and performance. Led by our Chairman, Roy Kapani, and an experienced executive leadership team, ECS provides our customers with solutions and services that support their critical needs and further mission objectives. This commitment has paved the way for expansive growth, year over year.

ECS gained market share in 2011 in the Department of Defense and Federal spaces through both organic and acquisition growth. In May, ECS completed its first strategic acquisition with the purchase of OAK Management, Inc., a leading provider of marine environmental services, ship systems engineering, maritime consulting and platform acquisition management. The OAK acquisition kicked off ECS’ intention to add tactical acquisitions as a part of its long term strategy to supplement and expand upon organic growth and to build enterprise value. ECS closed out 2011 with the acquisition of Paradigm Technologies, Inc. The Paradigm transaction added approximately 200 employees to ECS’ existing 900+ employees. Paradigm also added new Defense clients for ECS, including the Missile Defense Agency, the Navy’s Program Executive Officer for Integrated Warfare Systems, the United States Marine Corps, and the U.S. Marshals Service.

In 2012, ECS completed the acquisition of iLuMinA Solutions, Inc. iLuMinA brings large-scale Enterprise Resource Planning (ERP) software implementation and infrastructure design and development to ECS’ expanding capabilities.

ECS will continue to invest in corporate infrastructure and quality processes as we grow and enhance our ability to offer professional excellence to both our customers and our employees.

COMPANY SIZE
50 to 99 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2000
WEBSITE
http://www.ecs-federal.com/

Similar Job Searches