SIEM/Splunk Engineer - TS/SCI Cleared

Zachary Piper
Newington, VA, United States
10 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$165,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Big Data Cloud Computing Cluster Analysis Configuration Management Cyber Security Identity and Access Management Issue Tracking Systems Intrusion Detection and Prevention Intrusion Detection Systems
+26 more
Python (Programming Language) Networking Basics Parsing Performance Tuning Windows PowerShell Role-Based Access Control Ansible Security Assertion Markup Language (SAML) Security Information and Event Management Systems Integration Transmission Control Protocol (TCP) Scripting Transport Layer Security Google Cloud Cloud Platform System In-Plane Switching (IPS) Data Ingestion System Availability Mitre Att&ck Cyber Threat Analysis Firewalls (Computer Science) Git Information Technology Deployment Automation Splunk Security Orchestration, Automation & Response

Job description

Zachary Piper Solutions is seeking an Senior SIEM/Splunk to join a Federal Program located in Newington, VA, onsite 5 days per week. The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response., * Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.

  • Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
  • Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
  • Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
  • Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
  • Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
  • Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
  • Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
  • Maintain architecture documentation, operational procedures, playbooks, and technical standards., Key Words: SIEM, splunk, bash, python, powershell, aws, azure, gcp, mitre, soar, phantom, tcp, udp, upgrades, migrations, edr, fw, ids, ips, cloud logs, cim, mapping, iam, ssl, splunk enterpise, splunk es, spl, configure, manage, engineer, federal, cleared, army, navy, air force, defense, clearance, government, models, dashboards, data models, soc, sme, playbooks, architecture, scripts, scripting, incident response

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
  • 5-10+ years of hands-on experience with Splunk Enterprise and Splunk ES
  • Experience designing, deploying, and supporting enterprise-scale Splunk environments with clustering, high availability, and large-volume data ingestion.
  • Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
  • Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
  • Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
  • Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
  • Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
  • Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
  • Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
  • Active TS/SCI Security Clearance

Benefits & conditions

  • Salary Range: $165,000+ flexible based on experience
  • Comprehensive Benefits: Medical, Dental, Vision, PTO, and Sick Leave as required by law
  • Flexible working schedule
  • Unlimited opportunities for growth

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all