
Senior Security Engineer - Splunk
UltraViolet Cyber16 days ago
Base Salary
$140k - $175k/yr
Responsibilities
- Design, implement, maintain, and optimize complex Splunk deployments for security monitoring, threat detection, data ingestion, and search performance.
- Document Splunk architecture and lead security engineering roadmaps, modernization, consolidation, automation, scalability, and reliability improvements.
- Develop Splunk searches, dashboards, alerts, reports, and visualizations to enhance security operations.
- Manage index clustering, search head clustering, forwarder deployment, infrastructure planning, installation, configuration, and integrations.
- Troubleshoot complex Splunk performance, indexing, ingestion, parsing, storage, authentication, configuration, availability, and data-loss issues and provide root-cause analysis.
- Lead Cribl-to-Splunk integration and data pipeline optimization, including routing, filtering, transformation, data quality, and ingestion reduction.
- Integrate Splunk with enterprise security tools and data sources, including endpoint, firewall, vulnerability scanning, privileged access, encryption, key management, audit, and incident response systems.
- Serve as a point of contact for security tool operations and support Splunk engineers and cross-functional security teams.
- Participate in an on-call rotation for security incident response and collaborate with cross-agency security teams.
Requirements
- U.S. citizenship and the ability to pass a federal background investigation and government clearance process are required.
- A master's degree in cybersecurity, information security, or a related field plus 12 years of experience is required.
- At least 7 years of security engineering experience, including at least 3 years of advanced Splunk implementation experience, is required.
- Splunk Certified Architect or Splunk Certified Enterprise Security Admin certification is required.
- Experience designing and implementing Splunk Enterprise Security and Cribl in large environments is required.
- Strong knowledge of SPL query language, advanced search techniques, Splunk administration, and performance tuning is required.
- Experience creating custom Splunk dashboards, reports, and visualizations is required.
- Demonstrated expertise in security monitoring and SIEM technology is required.
- Experience implementing security controls aligned with NIST SP 800-53 is required.
- Preferred qualifications include federal agency security operations center experience, Splunk or Cribl certifications, CISSP, GCIA, GCIH, or Security+ certifications, government network security architecture experience, CISA directive and CDM program knowledge, cloud security monitoring with Splunk and Cribl, and Zero Trust architecture experience.
Benefits
- Hybrid work model requiring three days per week on-site near National Harbor, Maryland.
- Participation in an on-call rotation for security incident response.
- 401(k) with an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed.
- Medical, dental, and vision insurance available on the first day of the month following the first day of employment.
- Group term life, short-term disability, and long-term disability insurance.
- Voluntary life, hospital indemnity, accident, and critical illness coverage.
- Discretionary Time Off program and 11 paid holidays annually.
Tech Stack
Splunk