Enter a job title or keyword

SIEM Data Onboarding Engineer (Splunk)

EmergiTEL


Job Location:

Toronto - Canada

Hourly Salary: CAD 67 - 84
Posted: 12 September 2026 (3 days ago)
Application Deadline: 10 December 2026
Vacancies: 1 Vacancy

Job Summary

emergiTEL is hiring a Splunk Engineer for our client in the Professional Services industry. This is a Contract role.
Compensation: $67.79 - $84.74/hour
Location: Toronto Ontario Canada (Onsite/Remote EST Time Zone)
Job Description
  • Lead end-to-end Splunk data onboarding including requirements analysis ingestion design implementation validation optimization and troubleshooting.
  • Onboard a wide range of data sources including application logs servers databases network and security devices syslog feeds APIs and cloud platforms.
  • Configure and troubleshoot Splunk ingestion and parsing using HEC and Universal/Heavy Forwarders.
  • Configure sourcetypes indexes timestamps event parsing filtering routing and field extractions while resolving data quality and ingestion issues.
  • Normalize and map security data to the Splunk Common Information Model (CIM) including field mappings tags event types and data models.
  • Develop and enhance Splunk Enterprise Security (ES) use cases correlation searches detections alerts dashboards reports and SPL searches.
  • Optimize searches detections dashboards and scheduled jobs to improve performance and reduce false positives.
  • Configure maintain monitor and troubleshoot enterprise Splunk environments including distributed and clustered architectures.
  • Monitor platform health ingestion pipelines indexing and search performance resource utilization and capacity.
  • Perform root cause analysis performance tuning and operational support.
  • Maintain technical documentation onboarding procedures configuration standards and operational runbooks.
Qualifications
  • Extensive hands-on experience as a Splunk Engineer or Senior Splunk Engineer in enterprise-scale environments.
  • Strong expertise in Splunk data onboarding for complex and high-volume data sources.
  • Proven experience with Splunk Enterprise Security (ES) and security use case development.
  • In-depth knowledge of Splunk CIM data normalization field mapping tags event types and data models.
  • Strong understanding of Splunk architecture ingestion indexing forwarding search and distributed environments.
  • Practical experience with Splunk configuration files including and .
  • Advanced SPL development and optimization skills.
  • Experience with platform monitoring troubleshooting and performance tuning.
  • Knowledge of Linux/Unix networking APIs regular expressions and log formats.
  • Python or Shell scripting experience is considered an asset.
  • Excellent analytical problem-solving written and verbal communication skills.
  • Splunk certifications such as Enterprise Certified Admin Architect or Enterprise Security certifications are preferred.
Vacancy Status
This is an active position currently open for hiring.
Use of Artificial Intelligence
No artificial intelligence (AI) is used in the screening or selection process. All applications are reviewed by our recruitment team.
Equal Opportunity
emergiTEL is committed to creating a diverse and inclusive workplace. We welcome applications from all qualified individuals regardless of background. Hiring decisions are based solely on skills experience and qualifications relevant to the role.

Required Experience:

IC


About Company

Company Logo

Learn more

View Profile View Profile