
Tamkeen Technologies
Senior Splunk Engineer
- Permanent
- Riyadh, Saudi Arabia
- Experience 2 - 5 yrs
Job expiry date: 04/04/2026
Job overview
Date posted
18/02/2026
Location
Riyadh, Saudi Arabia
Salary
Undisclosed
Compensation
Comprehensive package
Experience
2 - 5 yrs
Seniority
Senior & Lead
Qualification
Bachelors degree
Expiration date
04/04/2026
Job description
The Senior Splunk Engineer at Tamkeen Technologies in Riyadh is a critical role responsible for enhancing the organization's IT security and operational monitoring capabilities through advanced Splunk solutions. This position involves designing, developing, and maintaining scalable Splunk infrastructure across multi-tenant MSSP environments, including administration of indexers, search heads, forwarders, and heavy forwarders. The engineer will implement best practices in data onboarding, including parsing, indexing, field extractions, and props/transforms, while optimizing SPL queries, dashboards, alerts, and reports to deliver actionable insights. Collaborating with SOC analysts, threat hunters, and client security teams, the role ensures comprehensive visibility and detection across IT environments. Responsibilities also include maintaining compliance with internal security policies and regulatory frameworks, implementing data retention policies, role-based access control, and delivering high availability and performance across the Splunk platform. The engineer will provide technical expertise and guidance to internal teams and MSSP clients, documenting architecture, configurations, processes, and operational runbooks, supporting client onboarding, use case development, and integrations with threat intelligence, SOAR, and third-party tools. This role requires proactive problem-solving, root cause analysis for performance and ingestion issues, and the ability to lead complex Splunk deployments in high-demand cybersecurity environments.
Required skills
Key responsibilities
- Administer and manage Splunk infrastructure across multiple clients in a multi-tenant MSSP environment
- Design and implement data onboarding processes including parsing, indexing, and field extractions
- Manage indexers, search heads, forwarders, and heavy forwarders for optimal performance
- Troubleshoot and resolve Splunk performance, search latency, and data ingestion issues
- Develop and optimize SPL queries, dashboards, alerts, and reports
- Ensure high availability, performance, and scalability of the Splunk platform
- Maintain forwarders, heavy indexers, search heads, and deployment servers
- Perform troubleshooting and root cause analysis for log ingestion and performance issues
- Support client onboarding, use case development, and data source integration
- Collaborate with SOC analysts, threat hunters, and client security teams to enhance visibility and detection
- Maintain compliance with internal security policies and relevant regulatory frameworks
- Implement role-based access control (RBAC), data retention policies, and compliance configurations
- Work closely with MSSP clients to understand their security monitoring requirements
- Provide Splunk expertise, troubleshooting, and best practices to internal and external stakeholders
- Produce documentation for architecture, configurations, processes, and operational runbooks
Experience & skills
- Bachelor’s degree in Information Security, Computer Science, or a related technical field
- 3–5 years of experience as a Splunk Administrator, preferably in an MSSP or multi-client environment
- Deep hands-on experience with Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk architecture components
- Strong knowledge of SPL, data onboarding (parsing, field extractions, props/transforms), and performance tuning
- Experience with Splunk integrations, including threat intelligence feeds, SOAR, and third-party tools
- Familiarity with Linux/Unix systems and scripting (Python, Bash, PowerShell)
- Strong understanding of SIEM use cases, threat detection, and log analysis
- Splunk certifications such as Splunk Certified Admin, Splunk ES Certified, or Splunk Architect