Splunk SOAR Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Leidos is hiring a Splunk SOAR Engineer to join our team in Suitland, MD. In this role, you will provide engineering, operations, and technical support for Security Information and Event Management (SIEM) platforms that support threat detection, compliance, and security incident management for the Office of Naval Intelligence’s Hopper Global Communications Center (HGCC). You will help develop and automate cybersecurity operations while supporting mission critical defensive cyber capabilities., * Design, deploy, and maintain EAC backend architecture.
- Administer the SOAR platform, including configuration, asset integrations, and custom fields.
- Design, develop, test, and maintain automated SOAR playbooks for alert triage, enrichment, and risk based response.
- Integrate SOAR with Splunk Enterprise Security, ticketing systems, and threat intelligence feeds.
- Manage clustering, replication, indexing performance, and license usage.
- Apply DISA STIGs, SRGs, and NAVINTEL Information Assurance baselines.
- Maintain version control, approval workflows, and playbook governance.
- Configure and maintain the secure transmission of Audit.XML records to Intelligence Community partners through ITS and troubleshoot transmission failures.
- Implement standard incident response workflows aligned with MITRE ATT&CK, NIST SP 800-61, and HGCC N62 Defensive Cyber Operations procedures.
- Travel may be required between the National Maritime Intelligence Center (NMIC) and other designated CONUS and OCONUS locations in support of program requirements.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Information Assurance, or a related discipline with 8+ years of relevant experience, or a Master’s degree with 6+ years of relevant experience. 15+ years of experience, including at least 10 years supporting LAN/WAN technologies, may be considered in lieu of a degree.
- Active TS/SCI security clearance.
- Active IAT Level III certification (such as CISSP).
- 8+ years of engineering experience supporting Computer Network Defense (CND).
- 6+ years of experience with Splunk, including Splunk Add-ons, Apps, Technology Add-ons (TAs), and Universal Forwarder.
- Expert knowledge of Splunk, including Splunk Enterprise, Splunk Enterprise Security, and Splunk SOAR.
- Significant experience with the System/Software Development Life Cycle (SDLC).
- Strong analytical and problem solving skills.
- Effective verbal and written communication skills.
Benefits & conditions
Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .
About the company
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Highest Paying Tech Companies for Developers
What’s the Difference between a Junior, Mid, and Senior Developer?
9 Ways to Make Money Hacking
Fully Remote Software Engineer Jobs