Splunk Developer

Urgent

Job Description

Splunk Developer – Technical Lead (ITSI)

Location: 2 days at Edinburgh

Role Summary

We are seeking an experienced Splunk Developer – Technical Lead with strong hands on expertise in Splunk Enterprise, IT Service Intelligence (ITSI), and Observability. The role requires deep technical knowledge combined with design leadership, stakeholder engagement, and production responsibility across complex enterprise platforms.

The candidate will lead Splunk solution design, mentor junior developers, and work closely with operations, SRE, and application teams to deliver scalable monitoring, service health, and analytics solutions.

Key Responsibilities Technical Leadership

  • Act as Technical Lead for Splunk implementations across monitoring, observability, and service intelligence use cases.
  • Own end to end Splunk solution design including data onboarding, data models, dashboards, alerts, and ITSI objects.
  • Review and govern Splunk development standards, SPL performance, and configuration best practices.
  • Provide technical guidance, mentoring, and code reviews for Splunk developers and support teams.

Splunk Core & ITSI

  • Design and implement Splunk ITSI components including KPIs & thresholds, Glass Tables, and episode review and correlation search tuning.
  • Build service centric monitoring aligned to business and application landscapes.
  • Configure entity extraction, service templates, and adaptive thresholds.
  • Lead onboarding of diverse data sources such as application logs, infrastructure metrics, APM data, cloud logs, and security events.
  • Design and optimise source types, field extractions, data models, and CIM compliance.
  • Ensure SPL queries and dashboards are performant and scalable.

Dashboards, Alerts & Analytics

  • Design meaningful alerts using correlation searches.
  • Translate operational and business requirements into actionable insights.

Observability & Production Support

  • Integrate Splunk with enterprise observability tools (APM, infrastructure monitoring, cloud platforms).
  • Support production incidents using Splunk, driving root cause analysis and post incident reviews.
  • Improve alert quality by reducing noise and false positives.

Stakeholder & Delivery Engagement

  • Collaborate with SRE / Ops teams, application & platform teams, and service management & ITIL functions.
  • Translate monitoring requirements into scalable technical solutions.
  • Participate in architecture discussions, audits, and compliance reviews.

Required Skills & Experience Splunk Expertise

  • Strong hands on experience with Splunk Enterprise.
  • Proven experience with Splunk ITSI (mandatory) including KPI design and service modelling, and Glass Tables.

Technical Skills

  • Excellent command of SPL (Search Processing Language).

Location