The Splunk / Cribl System Architect is responsible for designing, operating, and continuously optimizing Wacker’s centralized security analytics and observability platform.rnThe role ensures high‑quality data ingestion, platform scalability, cost efficiency, and operational resilience, supporting SOC, IT operations, and compliance use cases across on‑premises and cloud environments.
Platform Architecture & EngineeringrnrnDesign, implement, and maintain Splunk platform architectures (Search Head Clusters, Indexer Clusters, Forwarders, Deployment Server, SmartStore where applicable).rnDesign and operate Cribl architectures (Cribl Stream, pipelines, routing, and filtering strategies).rnEnsure high availability, scalability, security, and performance of the logging and analytics platform. [Job Descri...Architect | Word]rnrnData Ingestion, Normalization & QualityrnrnDesign and manage log ingestion pipelines from infrastructure, applications, network devices, cloud platforms, and security tools.rnDefine and enforce data parsing, enrichment, and normalization standards (e.g., CIM alignment).rnEnsure data reliability, completeness, and fitness for detection, monitoring, and compliance use cases.rnrnPerformance, Capacity & Cost OptimizationrnrnPerform capacity planning, performance tuning, and platform optimization for high‑volume log environments.rnOptimize data flows using Cribl to control ingestion costs and improve downstream efficiency.rnMonitor platform health and proactively mitigate performance or scaling risks.rnrnSecurity Operations & Compliance EnablementrnrnSupport SOC and ITSOC use cases including detection, investigation, and monitoring.rnEnsure platform configurations align with security, compliance, and audit requirements.rnSupport incident investigations by providing reliable, timely, and structured log data.rnrnGovernance, Automation & Continuous ImprovementrnrnEstablish platform standards, runbooks, and operational documentation.rnIdentify and implement automation opportunities to improve platform operations and reliability.rnCollaborate with security engineers, IT operations, and application teams to onboard new use cases and log sources.
5+ years of experience with Splunk platform engineering and administration.rnHands‑on expertise with Cribl Stream / Edge for log routing, filtering, and optimization.rnStrong knowledge of SPL, log parsing, and analytics design.rnExperience supporting SOC / SIEM / observability platforms in enterprise environments.rnFamiliarity with cloud platforms, Linux, networking, and security concepts.
No

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.