Splunk Security Engineer

Leidos, Inc.
Suitland-Silver Hill, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 195K

Job location

Suitland-Silver Hill, United States of America

Tech stack

Microsoft Windows
Microsoft Active Directory
API
Amazon Web Services (AWS)
Apache HTTP Server
Tomcat
Azure
Computer Security
Linux
DNS
VMware ESX Servers
IIS
Integrated Development Environments
Intrusion Detection and Prevention
Python
NetApp Applications
SharePoint
Security Information and Event Management
SQL Databases
Systems Integration
Network Routers
Firewalls (Computer Science)
Tanium Platform Expertise
Vcenter
Nessus
Enterprise Integration
RSA SecurID
Firepower
Splunk
Cisco networks
ServiceNow
VMware

Job description

Are you ready to turn your skills into real-world impact?

Join as a in and be at the forefront of mission-critical cybersecurity. From defending networks to building scalable automation, your work will shape the response and resilience of national operations.

As a core member of our security engineering team, you will:

  • Develop, maintain, and execute that interact across systems and devices.
  • Analyze log events, correlate data across multiple sources, and enhance threat detection and response workflows.
  • Using SOAR connectors, design integrations between and standard DoD products such as Trellix ePO, Tanium, Cisco (FirePower, ISE, Email Gateways, AMP, switch/routers), Palo Alto Firewalls, Microsoft Active Directory, DNS, Exchange, SharePoint, IIS, SQL, Apache, Tomcat, RSA SecurID, Tenable.SC and Nessus, VMWare vCenter/ESXi, ServiceNow, Azure and AWS, NetApp, Windows and Linux. Connectors may use APIs, tokens, or service accounts, so understanding these options is important.
  • Configure and manage , including maintaining CIM compliance, Risk-Based Alerting (RBA), ticketing, and SIEM integrations.
  • Update and configure new Enterprise Security Content Updates when released.
  • Lead the full lifecycle of automation - from concept through deployment to documentation and tuning.
  • Build visual dashboards, reports, and context-aware incident response tools.
  • Support operational readiness, compliance, and proactive detection technologies across endpoint, cloud, network, and email infrastructures.
  • Apply patches and upgrades to Splunk SOAR and connectors.
  • Maintain existing/create new fleet of Development VMs (Windows, Linux) that allow you to test and demonstrate playbook functionality.
  • Fully test and document playbook execution in the Development environment and be authoritative on presentation of playbook examples to new teams targeted for integration.

Requirements

  • Bachelor's degree and 8+ years of experience or Master's degree and 6+ years of experience. Additional experience, training, or certifications may be considered in lieu of a degree.

  • Current (e.g., Security+ CE) or the ability to obtain within 30 days of Leidos start date.

  • Current or the ability to obtain with 60 days of Leidos start date.

  • Current or the ability to obtain with 90 days of Leidos start date.

  • Experience with Splunk SOAR/Phantom: playbook development, troubleshooting, and integrations.

  • Deep expertise in , security event analysis, and Python-based automation.

  • Strong working knowledge of cross-platform integrations and security tool APIs.

  • Experience with process improvement in fast-moving security environments.

  • (e.g., CISSP).

  • Proficiency in standard DoD Security and Operational products such as Active Directory, DNS, FWs (packet flows), Email, ACAS, Trellix/Tanium, Splunk, STIGs, Windows/Linux and the standard services associated with these operating systems and products.

  • Technical writing skills for SOPs and integration documentation.

  • Completion of

  • Experience with integration and SOC-level triage workflows.

Apply for this position