Sr. Security Engineer

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Role Summary

The Splunk Platform Engineer is responsible for designing, onboarding, and optimizing log ingestion pipelines within the Splunk platform. This role focuses on data ingestion, parsing, normalization, and Common Information Model (CIM) compliance to ensure high‑quality, searchable, and scalable security and operational data. The engineer will work hands‑on with Universal Forwarders (UF), Heavy Forwarders (HF), and Cribl to improve data quality, performance, and cost efficiency across the Splunk ecosystem.

Key Responsibilities

Splunk Platform & Data Engineering

  • Design, implement, and manage end‑to‑end log ingestion pipelines into Splunk.
  • Onboard new data sources across infrastructure, security, cloud, and application platforms.
  • Configure and manage Universal Forwarders (UF) and Heavy Forwarders (HF) for secure and scalable data collection.
  • Perform data filtering, routing, masking, and enrichment using Heavy Forwarders and Cribl.

Parsing, Normalization & CIM

  • Develop and maintain props.conf and transforms.conf for accurate parsing, timestamping, and field extractions.
  • Normalize logs to Splunk Common Information Model (CIM) standards for consistent search, correlation, and reporting.
  • Troubleshoot parsing, indexing, and data quality issues across multiple log sources.

Cribl & Optimization

  • Implement and manage Cribl pipelines for data reduction, enrichment, routing, and cost optimization.
  • Optimize ingestion volumes and indexing strategies to improve Splunk performance and licensing efficiency.
  • Validate data integrity post‑processing and ensure downstream use case compatibility.

Platform Operations & Support

  • Monitor Splunk ingestion health, forwarder performance, and data latency.
  • Provide L2/L3 support for ingestion, parsing, and forwarder‑related issues.
  • Maintain platform documentation, ingestion standards, and operational runbooks.
  • Collaborate with SOC, Detection Engineering, and Security Engineering teams to support downstream analytics.

Required Skills & Experience

  • 2–5 years of hands‑on experience with Splunk platform engineering or SIEM data onboarding.
  • Strong experience with Splunk Universal Forwarders (UF) and Heavy Forwarders (HF).
  • Proven expertise in log parsing, normalization, and CIM compliance.
  • Hands‑on experience with Cribl for data routing, reduction, and enrichment.
  • Strong knowledge of log formats (JSON, syslog, CSV, XML) and data pipelines.
  • Proficiency in Splunk Search Processing Language (SPL) for validation and troubleshooting.

Preferred Qualifications

  • Experience supporting security telemetry (EDR, IAM, network, cloud, application logs).
  • Exposure to large‑scale Splunk environments in regulated enterprises.
  • Scripting experience (Python, Bash, PowerShell) for automation and validation.
  • Familiarity with Splunk indexer clustering, deployment server, and monitoring console.

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.