Back to search
Lintasarta Linkedin · Posted yesterday

Platform Engineer

Jakarta

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Roles and Responsibilities:


Infrastructure Architecture & Administration

  • Platform Management: Oversee the full lifecycle—architecture, deployment, patching, clustering, and health monitoring—of core SOC platforms (SIEM, SOAR, EDR, TIP).
  • Data Pipeline Engineering: Architect and manage high-volume data ingestion pipelines, ensuring logs from cloud environments, networks, and endpoints are cleanly parsed, normalized, and indexed.
  • Storage & Retention Optimization: Optimize index storage strategies, hot/cold data tier configurations, and long-term compliance log archival to balance operational speed with hardware costs.

Automation & Integration (SOAR)

  • API Integration: Connect disparate security platforms, infrastructure systems, and identity providers by writing robust, secure custom API integrations.
  • Playbook Infrastructure: Engineer the backend infrastructure, actions, and custom connectors required for Tier-2 and Incident Response teams to execute automated response playbooks.
  • Agent Deployment: Partner with IT and DevOps teams to manage the automated enterprise-wide deployment, tuning, and health verification of EDR and logging agents.

Performance Tuning & Reliability

  • Query Performance Optimization: Audit, test, and tune complex analytical queries (e.g., Splunk SPL, Sentinel KQL) written by detection engineers to prevent system resource exhaustion.
  • High Availability: Implement and test robust backup, disaster recovery, and failover strategies for all critical SOC infrastructure components to guarantee 24/7/365 uptime.


Technical Skills & Tools

Platform Infrastructure & Engineering

  • SIEM/Data Lake Engineering: Deep architectural knowledge of enterprise platforms, such as Splunk Enterprise (Clustering, Indexer/Search Head architecture), Microsoft Sentinel, Elastic Cloud (ELK), or Cribl Stream.
  • SOAR Infrastructure: Infrastructure-level experience managing orchestration engines like Palo Alto Cortex XSOAR, Splunk SOAR, or Swimlane.
  • DevOps & Infrastructure as Code (IaC): High proficiency deploying infrastructure and configurations using Terraform, Ansible, Docker, or Kubernetes clusters.

Linux Administration & Scripting

  • System Administration: Enterprise-level Linux (RHEL, Ubuntu) and Windows Server systems administration, including performance tuning, daemon management, and access controls.
  • Automation Languages: Advanced scripting capabilities in Python, Bash, or Go to build automated utilities, parse custom logs, and manipulate JSON/XML payloads over REST APIs.
  • Cloud Architecture: Deep experience managing native security logging mechanisms across AWS (CloudTrail, VPC Flow), Azure (Event Hubs), and GCP (Pub/Sub).


Experience & Qualifications

Required Experience

  • Total Systems Engineering Experience: Minimum of 5–7+ years of professional experience in Infrastructure Engineering, DevOps, Cloud Architectures, or Enterprise Systems Administration.
  • Splunk Platform Engineering Footprint: At least 3+ years of dedicated experience architecting, deploying, and maintaining large-scale Splunk environments, with explicit responsibility for managing Splunk Enterprise Security (ES) premium applications.
  • Architecture Scale: Documented history of engineering multi-tier Splunk environments (Clustered Indexers, Search Head Clusters, deployment servers) handling multi-terabyte per day data ingestion pipelines.


Splunk ES Specialized Experience

  • Data Model Acceleration: Proven experience configuring, tuning, and troubleshooting Data Model Accelerations (DMA) within Splunk ES to keep search head performance optimized without exhausting storage or CPU infrastructure.
  • CIM Compliance Engineering: Mastery of mapping unstructured log sources (firewall, cloud, identity, endpoint) to the Splunk Common Information Model (CIM) to ensure seamless alerting inside the ES incident review dashboard.
  • RBA Implementation: Direct hands-on experience structuring infrastructure to support Splunk Risk-Based Alerting (RBA) frameworks, including managing risk indexes and object attributions.
  • Data Stream Optimization: Proficiency utilizing Splunk Heavy Forwarders, Splunk Stream, or edge-routing technology (e.g., Cribl Stream, Kafka) to mask, filter, and drop duplicate event streams before they impact Splunk licensing costs.


Preferred Professional Certifications:

  • Splunk Enterprise Certified Architect
  • Splunk Core Certified Consultant
  • Splunk Enterprise Security Certified Admin (Highly Preferred)
  • Splunk Cloud Certified Admin
  • Certified Information Systems Security Professional (CISSP)
  • AWS or Microsoft Azure Solutions Architect


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search