Platform Engineer
Indexed description
Roles and Responsibilities:
Infrastructure Architecture & Administration
- Platform Management: Oversee the full lifecycle—architecture, deployment, patching, clustering, and health monitoring—of core SOC platforms (SIEM, SOAR, EDR, TIP).
- Data Pipeline Engineering: Architect and manage high-volume data ingestion pipelines, ensuring logs from cloud environments, networks, and endpoints are cleanly parsed, normalized, and indexed.
- Storage & Retention Optimization: Optimize index storage strategies, hot/cold data tier configurations, and long-term compliance log archival to balance operational speed with hardware costs.
Automation & Integration (SOAR)
- API Integration: Connect disparate security platforms, infrastructure systems, and identity providers by writing robust, secure custom API integrations.
- Playbook Infrastructure: Engineer the backend infrastructure, actions, and custom connectors required for Tier-2 and Incident Response teams to execute automated response playbooks.
- Agent Deployment: Partner with IT and DevOps teams to manage the automated enterprise-wide deployment, tuning, and health verification of EDR and logging agents.
Performance Tuning & Reliability
- Query Performance Optimization: Audit, test, and tune complex analytical queries (e.g., Splunk SPL, Sentinel KQL) written by detection engineers to prevent system resource exhaustion.
- High Availability: Implement and test robust backup, disaster recovery, and failover strategies for all critical SOC infrastructure components to guarantee 24/7/365 uptime.
Technical Skills & Tools
Platform Infrastructure & Engineering
- SIEM/Data Lake Engineering: Deep architectural knowledge of enterprise platforms, such as Splunk Enterprise (Clustering, Indexer/Search Head architecture), Microsoft Sentinel, Elastic Cloud (ELK), or Cribl Stream.
- SOAR Infrastructure: Infrastructure-level experience managing orchestration engines like Palo Alto Cortex XSOAR, Splunk SOAR, or Swimlane.
- DevOps & Infrastructure as Code (IaC): High proficiency deploying infrastructure and configurations using Terraform, Ansible, Docker, or Kubernetes clusters.
Linux Administration & Scripting
- System Administration: Enterprise-level Linux (RHEL, Ubuntu) and Windows Server systems administration, including performance tuning, daemon management, and access controls.
- Automation Languages: Advanced scripting capabilities in Python, Bash, or Go to build automated utilities, parse custom logs, and manipulate JSON/XML payloads over REST APIs.
- Cloud Architecture: Deep experience managing native security logging mechanisms across AWS (CloudTrail, VPC Flow), Azure (Event Hubs), and GCP (Pub/Sub).
Experience & Qualifications
Required Experience
- Total Systems Engineering Experience: Minimum of 5–7+ years of professional experience in Infrastructure Engineering, DevOps, Cloud Architectures, or Enterprise Systems Administration.
- Splunk Platform Engineering Footprint: At least 3+ years of dedicated experience architecting, deploying, and maintaining large-scale Splunk environments, with explicit responsibility for managing Splunk Enterprise Security (ES) premium applications.
- Architecture Scale: Documented history of engineering multi-tier Splunk environments (Clustered Indexers, Search Head Clusters, deployment servers) handling multi-terabyte per day data ingestion pipelines.
Splunk ES Specialized Experience
- Data Model Acceleration: Proven experience configuring, tuning, and troubleshooting Data Model Accelerations (DMA) within Splunk ES to keep search head performance optimized without exhausting storage or CPU infrastructure.
- CIM Compliance Engineering: Mastery of mapping unstructured log sources (firewall, cloud, identity, endpoint) to the Splunk Common Information Model (CIM) to ensure seamless alerting inside the ES incident review dashboard.
- RBA Implementation: Direct hands-on experience structuring infrastructure to support Splunk Risk-Based Alerting (RBA) frameworks, including managing risk indexes and object attributions.
- Data Stream Optimization: Proficiency utilizing Splunk Heavy Forwarders, Splunk Stream, or edge-routing technology (e.g., Cribl Stream, Kafka) to mask, filter, and drop duplicate event streams before they impact Splunk licensing costs.
Preferred Professional Certifications:
- Splunk Enterprise Certified Architect
- Splunk Core Certified Consultant
- Splunk Enterprise Security Certified Admin (Highly Preferred)
- Splunk Cloud Certified Admin
- Certified Information Systems Security Professional (CISSP)
- AWS or Microsoft Azure Solutions Architect
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search