Source description
About the role
Position: Splunk SME
Duration: 12 months with potential up to 18 Months
Location: Tempe, AZ - onsite every Thursday and every 3rd Wednesday of the month
Start Date: early to Mid-August
The team's scope is specifically Splunk on-premise, centered on use cases for NERC/CIP compliance across OT (primary) and Telecom teams. This role does not carry a traditional Enterprise Security (ES) use case — a separate team continues to run point on ES/SOC-facing security use cases separately.
Most immediate needs are: a Splunk architecture review (data collection and forwarder review), a platform health check, and support with compliance reporting.
Core Responsibilities
Conduct a Splunk architecture review — data collection and forwarder configuration/health — as an immediate first priority
Perform a platform health check and support compliance reporting deliverables
Provide hands-on Splunk SME support during the on-prem-to-managed transition, working alongside and mentoring another team member.
Support Splunk on-premise use cases for NERC/CIP compliance across OT (primary) and Telecom teams
Work within company's on-prem deployment and operations/compliance environment (Splunk SIEM), with NERC compliance as a baseline, must-have requirement
Help design and refine the indexing structure in coordination with multiple internal stakeholders
Support Cribl implementation as part of replacing the logging pipeline/infrastructure
Teach/mentor the team on content creation (searches, dashboards, correlation rules, alerting)
Understand and adapt to how a utility SOC/OT environment approaches change management differently than a traditional IT/network environment
Work closely with partners where platform/patching work intersects with SOC operations
Coordinate with SOC team where Splunk is shared across monitoring and compliance, without owning their ES use case
Required Skills & Experience
Strong hands-on Splunk experience — SIEM administration, SPL, dashboarding, content/use-case development
Experience conducting Splunk architecture/health assessments, including data collection pipeline and forwarder review
Direct utility industry experience strongly preferred — they are explicit that OT/compliance change management and operational context differ meaningfully from standard IT/network environments
NERC/CIP compliance experience — non-negotiable baseline, including compliance reporting
Experience with Cribl or logging pipeline/data routing tools a strong plus
Splunk Enterprise Security (ES) experience is not required for this role (owned by a separate team)
Comfort mentoring/upskilling a junior FTE resource, not just doing the work solo
Ability to work cross-functionally with multiple stakeholders on architecture decisions (indexing design, pipeline structure) across OT and Telecom teams
More at 3B Staffing