Senior Online Engineer

3 days ago

Toronto ON, Toronto Census Division, ON; Ontario, Canada PlanIT Search Full-time
Employment Type: Contract, 12 months to start We are looking for an experienced Senior Splunk Engineer to join our client on a 12-month contract with potential for extension. This is a hands‑on engineering role for someone who has strong experience supporting enterprise‑scale Splunk environments, with a particular focus on data onboarding, Splunk Enterprise Security (ES), CIM, security use cases, and platform engineering . Lead end‑to‑end Splunk data onboarding , from requirements analysis and ingestion design through implementation, validation, optimization, and troubleshooting. Onboard diverse and high-volume data sources, including application logs, servers, databases, network/security devices, syslog, APIs, and cloud platforms. Configure sourcetypes, indexes, timestamps, event parsing, filtering, routing, and field extractions. Troubleshoot data quality, ingestion, parsing, and field extraction issues. Normalize security data using the Splunk Common Information Model (CIM) , including field mappings, tags, event types, and data models. Tune searches, detections, dashboards, and scheduled jobs to improve performance, accuracy, and reduce false positives. Monitor ingestion pipelines, indexing/search performance, resource utilization, platform health, and capacity. Perform root-cause analysis and Splunk performance tuning . Create and maintain technical documentation, configuration standards, onboarding procedures, and operational runbooks. Extensive hands‑on experience as a Splunk Engineer / Senior Splunk Engineer in enterprise‑scale environments. Strong experience with Splunk data onboarding , including complex and high-volume data sources. Strong knowledge of Splunk CIM , including normalization, field mapping, tags, event types, and data models. Hands‑on experience with Splunk platform configuration, maintenance, monitoring, troubleshooting, and performance tuning. Working knowledge of Linux/Unix, networking, APIs, regex, and common log/data formats . Python and/or Shell scripting and automation experience is an asset. Strong analytical and problem‑solving skills with the ability to independently troubleshoot complex technical issues. Splunk certifications such as Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect , or relevant Splunk ES certifications are an asset. We celebrate diversity and are committed to creating an inclusive environment for all employees. This posting represents an active and genuine vacancy with one of Plan IT’s clients and is not intended for speculative or pipeline recruitment. Plan IT and/or its clients may use AI‑assisted tools from time to time to support the screening and evaluation of applications; however, these tools do not replace human judgment or decision‑making at any stage of the hiring process. #