Splunk Database Administrator

Whizdom ·whizdom.shazamme.com

Location Melbourne, Victoria, Australia
Work type Hybrid
Salary AUD 68 - 90 / hour
Type Full time
Level Mid
Source Shazamme
Information & Communication Technology (ICT)
Apply direct
Splunk Data Administrator
πŸ“ Melbourne VIC
⏳ 6+ Month Contract
πŸ’° Competitive Daily Rate

About the Role
We are working with a global consulting organisation delivering large-scale programs across government and enterprise environments. They are seeking a mid to senior Splunk Data Administrator to take ownership of data onboarding, normalization, and overall data quality across a complex hybrid Splunk environment (on-premise and cloud).

This is a hands-on role suited to someone who thrives in complex environments and enjoys working across the full data lifecycle, from ingestion through to optimisation and governance.

Key Responsibilities
  • Lead end-to-end onboarding of log sources, including requirements gathering, parsing, testing, and deployment
  • Drive CIM normalization and ensure alignment with Splunk data models to support security and operational use cases
  • Design and implement field extractions using regex, props.conf, transforms.conf, and structured parsing techniques
  • Manage and optimise Splunk data pipelines across hybrid environments, ensuring performance, reliability, and data quality
  • Configure and maintain Splunk components including Search Heads, Indexers, forwarders, and deployment infrastructure
  • Monitor ingestion performance, troubleshoot issues, and implement best practices for data governance and lifecycle management
Skills & Experience
  • 5–10 years’ experience in Splunk administration and data onboarding
  • Strong expertise in:
    • CIM normalization, data modelling, and SPL validation
    • Field extraction, parsing, and sourcetype configuration
    • Splunk architecture including Search Heads, Indexers, clusters, and forwarders
  • Experience working in complex or hybrid Splunk environments (on-premise and cloud)
  • Knowledge of Linux environments (RHEL, Amazon Linux)
  • Exposure to AWS services such as EC2, S3, IAM, and CloudWatch is highly regarded
  • Experience with automation tools such as Ansible, Terraform, or CI/CD pipelines is advantageous
Nice to Have
  • Splunk certifications (Admin, Power User, ES Admin)
  • Experience with Splunk Enterprise Security (ES)
  • Familiarity with modern ingestion methods such as HEC, APIs, or cloud-native logging tools
Candidate Requirements
  • Based in Melbourne or willing to relocate
  • Australian working rights required
We strongly encourage applications from candidates who are new to Australia or looking to gain local experience.
  • Open to Working Holiday Visa holders
  • No local experience required
Why Apply?
  • Opportunity to work on large-scale, enterprise Splunk environments
  • Exposure to modern cloud and hybrid architectures
  • Supportive team environment with strong onboarding and knowledge sharing
  • Ideal entry point into the Australian market with a global employer
πŸ“© Apply now or contact Dylan Sheoshker
πŸ“ž 0480 002 456
βœ‰οΈ dylans@whizdom.com.au

Frequently asked questions

Who is hiring for the Splunk Database Administrator role?
Whizdom is hiring for the Splunk Database Administrator position, a Shazamme client. Apply directly on the employer's career site.
Where is the Splunk Database Administrator job located?
The Splunk Database Administrator role with Whizdom is based in Melbourne, VIC, AU. The role is hybrid-friendly.
Is the Splunk Database Administrator role remote?
Yes β€” the Splunk Database Administrator position at Whizdom is hybrid. Candidates based in AU are preferred.
What does the Splunk Database Administrator role pay?
Whizdom lists the Splunk Database Administrator role at AUD 68–90 per hour.
Is the Splunk Database Administrator role full-time or contract?
This is a full time position at Whizdom.
What experience level is the Splunk Database Administrator role?
The Splunk Database Administrator position is aimed at mid-level candidates.
How do I apply for the Splunk Database Administrator role at Whizdom?
Apply directly on Whizdom's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS β€” no third-party form, no resume database.
Apply direct