Padmi

Splunk SME

United States · OnsitePosted 1 month ago
Infrastructure And DatabasesUnspecified
Apply at 3B Staffing

Opens the source posting on 3bstaffing.com

Source description

About the role

View original

Position: Splunk SME

Duration: 12 months with potential up to 18 Months

Location: Tempe, AZ - onsite every Thursday and every 3rd Wednesday of the month

Start Date: early to Mid-August

The team's scope is specifically Splunk on-premise, centered on use cases for NERC/CIP compliance across OT (primary) and Telecom teams. This role does not carry a traditional Enterprise Security (ES) use case — a separate team continues to run point on ES/SOC-facing security use cases separately.

Most immediate needs are: a Splunk architecture review (data collection and forwarder review), a platform health check, and support with compliance reporting.

Core Responsibilities

Conduct a Splunk architecture review — data collection and forwarder configuration/health — as an immediate first priority

Perform a platform health check and support compliance reporting deliverables

Provide hands-on Splunk SME support during the on-prem-to-managed transition, working alongside and mentoring another team member.

Support Splunk on-premise use cases for NERC/CIP compliance across OT (primary) and Telecom teams

Work within company's on-prem deployment and operations/compliance environment (Splunk SIEM), with NERC compliance as a baseline, must-have requirement

Help design and refine the indexing structure in coordination with multiple internal stakeholders

Support Cribl implementation as part of replacing the logging pipeline/infrastructure

Teach/mentor the team on content creation (searches, dashboards, correlation rules, alerting)

Understand and adapt to how a utility SOC/OT environment approaches change management differently than a traditional IT/network environment

Work closely with partners where platform/patching work intersects with SOC operations

Coordinate with SOC team where Splunk is shared across monitoring and compliance, without owning their ES use case

Required Skills & Experience

Strong hands-on Splunk experience — SIEM administration, SPL, dashboarding, content/use-case development

Experience conducting Splunk architecture/health assessments, including data collection pipeline and forwarder review

Direct utility industry experience strongly preferred — they are explicit that OT/compliance change management and operational context differ meaningfully from standard IT/network environments

NERC/CIP compliance experience — non-negotiable baseline, including compliance reporting

Experience with Cribl or logging pipeline/data routing tools a strong plus

Splunk Enterprise Security (ES) experience is not required for this role (owned by a separate team)

Comfort mentoring/upskilling a junior FTE resource, not just doing the work solo

Ability to work cross-functionally with multiple stakeholders on architecture decisions (indexing design, pipeline structure) across OT and Telecom teams

One address, no account. We’ll tell you when matching roles go live.

More at 3B Staffing

Related open roles

View all roles
Splunk SME at 3B Staffing · Padmi