Sce (Splunk Architect Engineer )
CurrentResponsible for day-day operation of large Splunk environment.Troubleshooting new and current data collection issuesTroubleshooting system issues that make the system unstable or unusable.Deployment and Managing supported and unsupported Splunk Add-ons that are required for specific data sourcesResponsible for Splunk Upgrades to all Splunk Enterprise serversIntegrations with other systems via API or other similar methodsProvide documentation such as body of evidence documents (as needed), engineering documents, change management documents, system security plans, and accreditation documentsDeliver a comprehensive Splunk deployment document to detail the specifications, deployment methods, and other architectural considerations to the production environment.Maintain a strict role-based access control solution around the data collected, to provide a need-to-know abilityForwarder Configurations and Deployments: Design and deploy forwarders rapidly with centralized configuration management (Splunk Deployment Server).Oversee Knowledge Object Management such as CIM management and tuningOversee Enterprise Security configurations and tuningExperience in the use of network monitoring tools with a strong understanding of network protocolsAbility to perform security analysis, development and implementation of security policies, standards and guidelinesProcess the On-boarding new devices/Customer into the Splunk.