Jacob Evans

Indianapolis, IN  · (260) 437‑1501 · jacob . [middle initial] . evans [at] gmail . com

Splunk Architect with a passion for DevOps and automating all the things


Experience

Sr Engineer; IT Security

Raymond James Financial
St. Petersburg, FL (Remote)

  • Lead architect of the global Splunk Cloud and on-premises environments including search heads, indexers, deployment servers, heavy/universal forwarders, and a distributed Syslog-NG infrastructure
  • Saved hundreds of thousands of dollars accelerating data models, creating summary indexes, tuning hundreds of scheduled searches and dashboards to reduce resource utilization
  • Led the large-scale upgrade of 42k Splunk universal forwarders across 10 siloed global teams
  • Design and implement automated workflows for incident detection through ticket creation and resolution, removing visibility gaps and improving MTTR
  • Collaborate cross-functionally with SRE, DevOps, IAM and security teams to deliver tailored solutions aligned with security and operational goals
  • Drove end-to-end migration to the Splunk Victoria Experience leading planning, prerequisite validation, execution, and post-migration support

February 2023 - Current

Sr DevOps Engineer

TriMedx, LLC
Indianapolis, IN (Remote)

  • Utilized Puppet to automate the configuration management of Splunk environments including Splunk upgrades (reducing upgrade time from hours to less than 15 minutes)
  • Automated deployments using API/ACS to eliminate human error and decrease deployment times by over 90%
  • Moved all Splunk configurations into GitHub to ensure ISO compliance and enforced proper Splunk source control management and SDLC
  • Standardized SDLC documentation using Confluence templates and Jira automation to automatically create subtasks and documentation
  • Initiated and created Azure DevOps pipeline to increase Splunk development automation
  • Created Splunk automated testing using Python and the Splunk API to automate unit tests and quality assurance
  • Created monitoring searches to proactively alert the team on issues in the system, and display the current status of any potential issues in real-time dashboards

October 2022 - February 2023

Splunk Administrator [Sr DevOps Engineer]

TriMedx, LLC
Indianapolis, IN (Remote)

  • Primary contact for all Splunk development, testing, and operations
  • Created, configured, and maintained two Splunk Enterprise instances for development and testing
  • Migrated all Splunk servers from Windows to Linux
  • Eliminated over 95% of custom data processing scripts to reduce overhead and potential failure points
  • Created Confluence documentation for Splunk configuration, testing, and high-level code explanations
  • Created monitoring searches to proactively alert the team on issues in the system, and display the current status of any potential issues in real-time dashboards
  • Mentoring seven team members in Splunk development and best practices

May 2021 - October 2022

Splunk Administrator

Pernix Consulting, LLC
Arlington, VA

  • Created interactive dashboard to display security compliance for Oracle 12c databases based on client’s standard operating procedures. Components include: data inputs (custom logs, SQL, PowerShell scripts, file security auditing), advanced searches, and dashboards to visualize security compliance
  • Created fully-documented custom JavaScript/CSS-based Splunk executive dashboard used throughout the bureau to monitor all 20+ critical applications using the Splunk Web Framework
    • Built dynamically to allow new features (KPIs) to be implemented in minutes
    • Includes the entire pipeline from Splunk architecture, data ingestion, normalization (CIM), transformation, field extraction, and analysis to user-facing reports, alerts, and dashboards with <1 second load times
    • Includes multiple dashboards granting privileged users limited abilities to make changes normally reserved for Splunk administrators (e.g. temporarily disabling alerts or updating lookups)
    • Implemented automatic resolution for common issues freeing 10% of system administrators’ time to focus on non-repetitive tasks
  • Created dynamic, templated Splunk apps giving system owners a holistic view of their entire application with the ability to customize individual dashboards to each owners’ needs
  • Rebuilt environment including system architecture, data ingestion, data normalization, search optimization, reusable macros, automated forwarder updaters, deployment restructuring, and UI modifications with best practices and the Common Information Model (CIM) in mind to enhance functionality, readability, and simplicity
    • Significantly enhanced production monitoring for quicker issue identification and resolution
    • Decreased internal production Splunk error counts by 80% (down from millions per day)
    • Added dynamic recipients to alerts based on conditions in the results to optimize alert distribution
    • Installed, upgraded, and configured Splunk Enterprise and splunkbase apps
  • Built and configured a brand new development Splunk environment on Azure
  • Wrote technical documentation in Confluence for most work especially architectural and best practice updates

April 2019 - July 2020

Senior Consultant

CGI Federal
Arlington, VA

  • Built Splunk up from a fresh install to actively monitoring hundreds of VMs from architecture to GUI components
  • Architected indexes, indexers, cluster master, and deployment server according to Splunk best practices
  • On-boarded and normalized hundreds of log types into Splunk such as: OS data, Active Directory, IIS, Oracle database (DB Connect), Tuxedo, Control-M, WebLogic, and webMethods data including many DoS external integrations
  • Created numerous Splunk reports, alerts, and interactive dashboards to track: successful and failed transactions (in to, out of, and/or through the system), system errors, timeouts, interactive log analysis, security, etc.
  • Automated the maintenance and monitoring of three production systems and 25 non-prod environments with Splunk, Control-M, webMethods, batch, and PowerShell to reduce resolution time and automatically resolve issues
  • Acted as the main point of contact to identify and resolve production issues involving the full application stack containing: Oracle database, webMethods, Tuxedo, WebLogic, IIS, and ext. integrations (SOAP, HTTP, JMS, API)
  • Automated code deployments using Control-M, SQL, Windows cmd, and PowerShell to reduce development and production upgrade time by up to 80% and eliminate human error
  • Optimized slowest multi-day database SQL statements saving over 80 hours of production downtime for a major upgrade, and reduced execution time of sensitive data scrub SQL scripts by 70% while improving data integrity
  • Provided day-to-day technical support as the primary point of contact supporting 15 functional analysts for issues, enhancements, script reviews, and other technical inquiries especially related to advanced SQL data analysis
  • Mentored four new hires on business processes, development, system monitoring, and issue resolution
  • Wrote technical documentation in Confluence for all work performed (code deliveries, production issues, etc.)

September 2016 - April 2019

Consultant (PeopleSoft Developer)

Oracle
Arlington, VA

  • Improved performance on five paramount data conversion applications by up to 30%
  • Created three end-to-end custom conversion programs to populate application with legacy data
  • Wrote and updated SQL for Oracle database optimization, customization, maintenance, and reporting
  • Identified, documented, tested, and reapplied all conflicting customizations to upgraded environments
  • Mentored college hire to fulfill client’s expectations and deadlines

June 2014 - September 2016

Technical Consultant (PeopleSoft Developer)

Oracle
Durham, OR

  • Tested and verified functionality of Agile development; tracked with Jira
  • Created design documents on evolving Siebel, OPA, and Oracle database logic, infrastructure, and integration

September 2013 - June 2014

Software Developer (Summer Intern)

Raytheon
Fort Wayne, IN

  • Automated C++ code creation directly from requirements documentation
  • Resolved issues and enhanced functionality of custom bug-tracking Java app involving dynamic SQL generation
  • Developed Perl scripts to dynamically generate SQL scripts to upgrade a local database to a multi-site implementation maintaining ACID properties

(summers) May 2009 - August 2012


Education

Indiana University - Bloomington

Bachelor of Science
Computer Science
Minor
Business

GPA: 3.10

August 2009 - May 2013

Homestead High School

Fort Wayne, IN

GPA: 3.88

August 2005 - May 2009

Skills

Skills, Programming Languages, & Tools
  • Automation
  • Scripting
  • Regular Expressions
  • Windows
  • PowerShell
  • cmd
  • Oracle / Databases
  • SQL & PL/SQL
  • Jira
  • Confluence
  • Technical Documentation
  • System Integration
  • JSON
  • YAML
  • XML
  • Linux
  • Bash
  • AWS & Azure
  • Azure DevOps / Pipelines
  • Visual Studio Code
  • Python
  • Perl
  • HTML, CSS, & JavaScript
  • Git & GitHub
  • Terraform
  • Ansible
  • Puppet
  • Eclipse
  • Active Directory
  • C, C++, and Java
  • APIs & Web Services

Splunk-specific
  • Certified: Splunk Cloud Admin, Splunk Architect, Splunk Admin, Splunk Advanced Power User, and Splunk Enterprise Security Admin
  • Versions 6.x to 9.x
  • 15+ TB/day; 1k+ SVC; 50k+ UF environments
  • CIM (Common Information Model) Compliance
  • Advanced SPL (Splunk Processing Language)
  • Data on-boarding & normalization
  • Data models
  • Summary Indexes
  • Metrics Indexes
  • Qmulos
  • Interactive Dashboarding
  • Splunk Web Framework
  • Splunk Enterprise, Forwarder, and app/add-on Upgrades
  • Searches, Reports, and Alerts
  • Search & Dashboard Optimization
  • Environment Troubleshooting & Tuning

Awards

  • 2025 (Raymond James) - Multiple formal appreciation awards for developing innovative solutions, delivering under pressure, and providing critical after-hours support during high-impact platform incidents
  • 2018 (CGI) - Company-wide recognition from C-suite executives for extraordinary efforts during a low-staffed and demanding period of the project
  • 2018 (CGI) - "Spotlight Award" for continually accepting additional responsibilities while both exceeding existing duties and training multiple new hires
  • 2015 (Oracle) - "Self-Initiative Spotlight" for quickly training college hire while exceeding own expectations

Languages

  • English
  • Spanish

Interests

Non-technical

My latest passion is scuba diving. My favorite diving spot so far is the reef just off of San Pedro, Belize. I've swam with reef sharks and whale sharks and speared lionfish. I've swam with wild dolphins, hand-fed sting rays and tarpon, and hand-caught spiny lobsters. I love the ocean and spend as much time as possible in and around it.

I enjoy being outdoors whenever I can whether it be yard work, mountain hiking, or running.

My winter hobby is snowboarding in Michigan and making it out to Colorado when possible.

I also love finance and investing and stay up to date with America's S&P 500 companies and the latest finance news. This includes cryptocurrency - I bought my first bitcoin back in mid 2013 for a cool cost of $93. It has now breached $100k (if only I had held the whole time!). I have a home-built PC (AMD all the way) and mined Ethereum and Electroneum back when it was profitable. The PC has now been converted to a home lab server running Proxmox.

Technical

  • Subscribing to way too many Terraform, Ansible, Splunk, and other automation and cloud GitHub repositories
  • Listening to podcasts (e.g. This Week In Tech, Daily Tech News Show, Security Now) and tech YouTube channels
  • Attended Splunk .conf2019 in Vegas, and have since participated in the virtual Splunk, AWS:ReInvent, GitHub Universe, Puppet, Atlassian, and Hashicorp conferences. I attended Splunk .conf in 2021 and then again in-person in 2022 and am aiming to go again in 2025.
  • Attend any Cloud, automation, or Splunk live events that come my way to stay up to date with the latest and greatest best practices. A great example of this is the weekly Cloud Posse office hours where this forward-thinking organization touches on the latest and greatest and other related Cloud + DevOps concepts
  • Playing with the latest and greatest automation tools
    • My home network runs on UniFi equipment with a wireless backup. I'm keeping an eye on local deals to get a real server rack going.
    • For home automation, I have Ring and Alexa integrated with Home Assistant, and I have all of that integrating with Apple Home. Everything down to the fire alarms are smart.
    • This website is automated with Terraform and hosted entirely on AWS, although I'm working on moving it to Google Sites
    • I am working on a 100% automated distributed Splunk instance using Terraform, Ansible, and SmartStore on AWS with configurations stored in private (for now) Git repositories. I currently have the Terraform and Ansible working to set up the environment and install Splunk
    • I am highly curious about containerization software and am getting started with it on my home lab Proxmox server.