SIEM/Splunk Engineer - TS/SCI Cleared
Zachary Piper
Newington, VA, United States
10 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$165,000.0
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Bash Shell
Big Data
Cloud Computing
Cluster Analysis
Configuration Management
Cyber Security
Identity and Access Management
Issue Tracking Systems
Intrusion Detection and Prevention
Intrusion Detection Systems
+26 more
Python (Programming Language)
Networking Basics
Parsing
Performance Tuning
Windows PowerShell
Role-Based Access Control
Ansible
Security Assertion Markup Language (SAML)
Security Information and Event Management
Systems Integration
Transmission Control Protocol (TCP)
Scripting
Transport Layer Security
Google Cloud
Cloud Platform System
In-Plane Switching (IPS)
Data Ingestion
System Availability
Mitre Att&ck
Cyber Threat Analysis
Firewalls (Computer Science)
Git
Information Technology
Deployment Automation
Splunk
Security Orchestration, Automation & Response
Job description
Zachary Piper Solutions is seeking an Senior SIEM/Splunk to join a Federal Program located in Newington, VA, onsite 5 days per week. The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response., * Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.
- Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
- Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
- Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
- Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
- Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
- Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
- Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
- Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
- Maintain architecture documentation, operational procedures, playbooks, and technical standards., Key Words: SIEM, splunk, bash, python, powershell, aws, azure, gcp, mitre, soar, phantom, tcp, udp, upgrades, migrations, edr, fw, ids, ips, cloud logs, cim, mapping, iam, ssl, splunk enterpise, splunk es, spl, configure, manage, engineer, federal, cleared, army, navy, air force, defense, clearance, government, models, dashboards, data models, soc, sme, playbooks, architecture, scripts, scripting, incident response
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
- 5-10+ years of hands-on experience with Splunk Enterprise and Splunk ES
- Experience designing, deploying, and supporting enterprise-scale Splunk environments with clustering, high availability, and large-volume data ingestion.
- Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
- Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
- Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
- Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
- Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
- Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
- Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
- Active TS/SCI Security Clearance
Benefits & conditions
- Salary Range: $165,000+ flexible based on experience
- Comprehensive Benefits: Medical, Dental, Vision, PTO, and Sick Leave as required by law
- Flexible working schedule
- Unlimited opportunities for growth
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
over 3 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
23 days ago