Mid-Level Splunk Analyst; Migration Specialist
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Data Analyst, Data Security, Data Engineer
Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.
By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.
Kentro is seeking a dedicated Mid-Level Splunk Analyst to support a high-profile migration effort for a major financial institution. This role focuses on the technical execution of migrating observability workloads from Splunk Observability Cloud (SOC) to Observe Inc.
The ideal candidate is a proficient Splunk practitioner who is eager to expand their skillset. While deep expertise in Observe is not required on day one, you must be willing to receive training in Observe and quickly apply that knowledge to translate complex queries and optimize data environments. You will work alongside IT architects and stakeholders to ensure seamless data transfer, query translation (SPL to OPAL), and post-migration optimization in a 24/7 operational environment.
ResponsibilitiesMigration Execution & Query Translation
- Execute the inventorying of dashboards and saved searches via SOC REST APIs to prepare for migration.
- Manually translate Splunk (SPL) queries into Observe (OPAL) with high semantic fidelity, ensuring critical financial logic (e.g., fraud detection filters) is preserved.
- Strict adherence to security and standards: perform all code translations and query logic updates manually or via approved scripts; the use of AI tools (e.g., O11y GPT) is strictly prohibited for this project due to security and accuracy requirements.
- Assist in configuring data ingestion pipelines using Open Telemetry agents and intermediaries like Cribl or Fluent Bit.
- Map data models to Observe’s Snowflake‑backed data lake and implement sampling strategies (e.g., 10‑20% for traces) during testing phases.
- Rebuild and validate dashboards in the Observe UI/API for real‑time monitoring.
- Conduct parallel query comparisons and replay scripts to validate data accuracy between the legacy Splunk environment and the new Observe environment.
- Monitor ingestion health and anomaly detection post‑migration to ensure user adoption and reduce alert fatigue.
- Maintain rigorous Git‑versioned documentation of all migration scripts, configurations, and rollback plans.
- Participate in retrospectives to refine processes for financial audits and scalability.
This position can be performed remotely within the United States and will support Eastern Time working hours.
- Education – Bachelor’s degree (BA/BS) in Computer Science, Information Systems, Engineering, or a related field.
- 3–5 years of hands‑on experience in Splunk engineering or analysis, specifically focused on event processing and dashboard management.
- Proven experience working in complex IT environments; prior experience in the financial sector is highly valued due to the low‑latency nature of the data.
- Deep Splunk proficiency: strong command of SPL, knowledge management, pre/post indexing data transformations and event management, as this will be the foundation for learning Observe.
- Scripting skills: competency in Python or Bash for API interactions (e.g., Splunk SDK) and automation tasks.
- Infrastructure as Code (IaC): familiarity with tools like Terraform or Ansible for configuration management.
- Ability to explain technical concepts (such as query logic) to non‑technical stakeholders or compliance teams.
- Strong problem‑solving skills under pressure, particularly regarding data accuracy in volatile market environments.
- Splunk
Certifications:
Certified Power User, Admin, or Architect credentials. - Observability exposure: prior exposure to Observe Inc. or the OPAL language is a plus, though comprehensive training will be provided.
- Intermedia…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).