> Markdown version of [/jobs/ext/436511-senior-siem-engineer](https://www.wearedevelopers.com/jobs/ext/436511-senior-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SIEM Engineer - **Company:** AMERICAN SYSTEMS - **Location:** Malmstrom Air Force Base, MT, United States - **Experience:** Expert - **Salary:** $175,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Proxy Servers, Bash Shell, Configuration Management, Cyber Security, Information Systems, Data Normalization, Linux, Distributed Systems, Networking Hardware, Intrusion Detection Systems, Python (Programming Language), Network Architecture, Performance Tuning, Windows PowerShell, Role-Based Access Control, Ansible, Runbook, Security Information and Event Management, Data Streaming, Systems Integration, Data Logging, Network Routers, Data Processing, Scripting, In-Plane Switching (IPS), Data Ingestion, Firewalls (Computer Science), Information Technology, Puppet, Terraform, Splunk, Data Pipelines, Vulnerability Analysis - **Published:** June 1, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a796fade39a65ac5 ## About the Role Do you have experience in Windows?, Do you have a Bachelor's degree?, * Active TS/SCI with CI Poly clearance (or eligibility) as required by the program. * Bachelor's degree in computer science, Information Security, Information Systems, or equivalent experience. * 6 - 8 years of experience with approximately 4-8 years of IT/cybersecurity experience, with at least 3+ years of hands-on SIEM * Demonstrated experience supporting Splunk in highly regulated or secure environments (DoD, IC, federal, defense contractor, or similar). * Proficiency with SPL, including complex searches, statistical commands, sub searches, lookups, and dashboard creation. Experience onboarding and normalizing data from: * Windows and Linux systems * Network infrastructure (routers, switches, firewalls, proxies) * Security tools (AV/EDR, IDS/IPS, vulnerability scanners, identity systems) * Strong understanding of information security principles and controls (logging, monitoring, auditing, least privilege, configuration management). * Familiarity with NIST 800-53, RMF, JSIG, or similar frameworks applicable to classified systems. Preferred Qualifications * Splunk certifications (e.g., Splunk Core Certified Power User, Splunk Core Certified Admin, Splunk Enterprise Security Certified Admin). * Experience operating Splunk in air-gapped, disconnected, or cross-domain (CDS) architectures. * Scripting skills (Python, PowerShell, Bash) for automation, integrations, and data manipulation. * Experience with configuration management and infrastructure-as-code (Ansible, Puppet, Chef, Terraform, or similar). * DoD 8570/8140-compliant certification (e.g., Security+, CySA+, CASP+, CISSP, GSLC, GSEC) as required for IAT/IASAE roles. * Background in one or more of: systems administration, network engineering, or cyber engineering in classified environments. Skills & Competencies * Ability to work effectively in a classified, process-driven environment with strong attention to detail and documentation. * Strong analytical and problem-solving skills; able to independently diagnose Splunk and data pipeline issues. * Clear and concise communication skills for collaboration with technical teams and security leadership. * Self-directed and able to prioritize tasks to support mission and compliance deadlines. ## Description AMERICAN SYSTEMS is seeking a professional with 8 - 10 years of experience and TS/SCI Clearance to be our next Senior Splunk Engineer at Malmstrom AFB, Montana. Platform Engineering & Administration * Install, configure, and maintain Splunk Enterprise and Splunk ES in classified, air-gapped, or cross-domain environments. * Manage distributed architectures (indexers, search heads, cluster masters, deployment servers, forwarders) with a focus on reliability, performance, and security. * Perform upgrades, patching, app deployment, performance tuning, and capacity planning. * Implement and maintain backup/restore, DR procedures, and system hardening in accordance with DoD/IC and organizational policies. Data Onboarding & Normalization * Onboard logs from servers, network devices, security appliances, applications, and specialized classified systems. * Develop and manage inputs, props, transforms, field extractions, and parsing to ensure high-quality, normalized data (CIM-compliant where applicable). * Work with system owners and engineers to define logging requirements that support auditing, incident reconstruction, and compliance. * Integrate Splunk with existing security tooling and infrastructure (e.g., host-based security, IDS/IPS, vulnerability scanners, identity systems). Detection, Dashboards & Reporting * Develop searches, correlation logic, alerts (where appropriate), and dashboards to surface security-relevant activity, system health, and compliance status. * Create role-specific dashboards for cybersecurity staff, ISSOs/ISSMs, system administrators, and leadership. * Support audit and inspection preparation (e.g., RMF, JSIG, NIST 800-53, CNSSI 1253) by building reports and evidence queries from Splunk. * Implement and maintain data models, lookups, and other knowledge objects to support efficient analysis and reporting. Security & Compliance Alignment Ensure Splunk configurations and data flows comply with classified environment requirements, including handling caveats, data segregation, and need-to-know. * Implement strict RBAC, data access controls, and logging of administrative actions. * Support RMF and related processes by providing visibility into control effectiveness (e.g., AU-2, AU-6, AU-12, SI-4). * Assist with continuous monitoring activities using Splunk as a key evidence and monitoring platform. Collaboration & Technical Leadership (Non-SOC) * Collaborate with cybersecurity engineers, ISSOs/ISSMs, system administrators, and network engineers to embed Splunk into system designs and modernization efforts. * Provide expert guidance on how to leverage Splunk for troubleshooting, audit support, and security visibility. * Mentor junior engineers and administrators on Splunk best practices, SPL queries, and platform usage. * Contribute to Splunk standards, runbooks, and engineering documentation tailored for the classified environment. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)