Junior Splunk Administrator (Application Monitoring & ITSM Integration) Remote
Citizenship/Clearance Required: US Citizenship/ Public Trust
Position Overview:
Ellumen is seeking a detail-oriented Splunk Analyst to support application-level monitoring and automated incident response through integrated ticketing systems. This role centers on developing Splunk searches, dashboards, and alerts to ensure real-time visibility across healthcare application environments. The analyst will also build and maintain connections between Splunk and the ITSM platform to drive fast, informed triage. Ideal candidates bring strong logging fundamentals, some cybersecurity awareness, and a comfort level working within military or federal networks.
Key Responsibilities:
Application-Level Log Monitoring (Splunk-Focused):
- Analyze and visualize logs from application servers, middleware, and OS-level sources using SPL
- Create dashboards and visual tools to monitor performance, detect errors, and observe behavior across application tiers
- Develop actionable alerts based on KPIs, error patterns, or specific log triggers
- Normalize diverse log formats (e.g., JSON, XML, syslog, HL7) through field extractions, lookups, and enrichments
- Refine alert logic to minimize false positives and support downstream ticketing
ITSM Ticketing Integration:
- Build and maintain automated workflows from Splunk to ITSM platforms (e.g., Jira Service Management, ServiceNow) via REST API or webhooks
- Format JSON payloads to capture log context including hostname, timestamp, error type, and metadata
- Authenticate securely using API keys or service credentials
- Ensure created tickets are enriched and structured for efficient triage and response
- Understand ticket lifecycle and how monitoring data improves ITSM outcomes
- This is not a complete list of responsibilities. Other tasks may be required as needed
Preferred Qualifications:
- 1-2 years of hands-on Splunk experience in application monitoring or observability roles
- Associate's or Bachelor's degree in Cybersecurity, Information Systems, or related technical field
- Familiarity with NIST RMF, STIGs, or audit/compliance frameworks
- Understanding of Splunk's role in anomaly detection, security alerting, and log review
- Awareness of multi-tiered government/military networks (NIPRNet, JMN, SIPRNet) and how segmentation affects monitoring
Desired Skills:
- SPL (Search Processing Language)
- Log format familiarity: JSON, XML, syslog, HL7, multi-line application errors
- REST API/webhook integration fundamentals
- Ticket lifecycle understanding in Jira Service Management, ServiceNow, or similar
- Comfortable working within DoD, federal healthcare, or contractor-hosted IT environments
|