> Markdown version of [/jobs/ext/1848878-splunk-siem-data-onboarding-engineer](https://www.wearedevelopers.com/jobs/ext/1848878-splunk-siem-data-onboarding-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Splunk SIEM Data Onboarding Engineer - **Company:** Booz Allen Hamilton Inc. - **Location:** Reston, VA, United States - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Microsoft Windows, Bash Shell, Cyber Security, Linux, JSON, Python (Programming Language), Networking Basics, Windows PowerShell, Regular Expressions, Ansible, Security Information and Event Management, Syslog, Tcpdump, Wireshark, Extensible Markup Language (XML), Scripting, Load Balancing, Data Ingestion, Firewalls (Computer Science), Git, Selinux, Information Technology, Data Management, Restful APIs, Splunk, Software Version Control, Data Pipelines, User Administration - **Published:** July 13, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9028247/splunk-siem-data-onboarding-engineer ## About the Role * 2+ years of experience managing and configuring Splunk, and configuring Cribl sources, destinations, routes, and collectors * 2+ years of experience in Splunk architecture, including indexers, search heads, forwarders, and deployment server * 2+ years of experience building pipelines to parse, normalize, enrich, mask or dedup, and route data to Splunk * 2+ years of experience authoring or maintaining props.conf, transforms.conf, inputs.conf, outputs.conf, and packaging apps or TAs * 2+ years of experience in Linux and Windows administration, including file paths, services, permissions, and log locations * 1+ years of experience with Splunk REST API for automation and operational tasks * 1+ years of experience with Cribl Redmap or JavaScript functions * Active TS/SCI clearance; willingness to take a polygraph exam * Associate's degree and 5+ years of experience supporting IT projects and activities, Bachelor's degree and 3+ years of experience supporting IT projects and activities, Master's degree and 1+ years of experience supporting IT projects and activities, or 10+ years of experience supporting IT projects and activities in lieu of a degree * Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX, CCNP Security, CISA, CISSP, GCED, GCIH, or CCSP Certification , and a DoD 8570 Cyber Security Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification , within 30 days of start date * 2+ years of experience with networking fundamentals, including TCP / UDP, TLS, syslog transport, firewall ports, and common transport issues * 2+ years of experience in basic troubleshooting with tools such as tcpdump or wireshark, basic vi / vim usage, setfacl, and SELinux * 1+ years of experience with STIGs or other organizational hardening standards working in regulated environments * 1+ years of experience with regex skills for field extraction and event breaking * Experience in SPL for validation, troubleshooting, and basic dashboards * Experience with scripting languages such as Python, Bash, or PowerShell * Experience with load-balancer fundamentals * Knowledge of common log formats such as syslog, Windows Event, JSON, CSV, and XML * Knowledge of Git for code version control * Knowledge of Ansible playbooks ## Description The Splunk SIEM Data Onboarding Engineer is responsible for managing and enhancing our Splunk environment to ensure seamless data ingestion, analysis, and visualization. This role demands a deep understanding of Splunk architecture, data onboarding, and user management to support business needs and security operations. * Design, deploy, and manage Splunk infrastructure. * Develop and maintain Splunk dashboards, queries, and alerts. * Integrate Splunk with various data sources to ensure comprehensive data ingestion. * Monitor and troubleshoot Splunk performance issues. * Collaborate with cross-functional teams to gather requirements and provide Splunk solutions. * Implement and enforce best practices for Splunk data management and retention. * Provide user training and support for Splunk- related activities. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)