SIEM/Splunk Engineer - TS/SCI Cleared
Zachary Piper Solutions · Newington, VA · 4 days ago
On-siteEngineering$165k/yrFull-time
Zachary Piper Solutions is seeking a Senior SIEM/Splunk Engineer to join a Federal Program located in Newington, VA, onsite 5 days per week.
About the role
The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response.
Responsibilities
- Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.
- Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
- Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
- Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
- Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
- Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
- Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
- Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
- Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
- Maintain architecture documentation, operational procedures, playbooks, and technical standards.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience).
- 5–10+ years of hands-on experience with Splunk Enterprise and Splunk ES.
- Experience designing, deploying, and supporting enterprise-scale Splunk environments with clustering, high availability, and large-volume data ingestion.
- Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
- Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
- Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
- Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
- Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
- Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
- Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
- Active TS/SCI Security Clearance.
Pay
Salary Range: $165,000+ (flexible based on experience).
Benefits
- Comprehensive medical, dental, and vision coverage.
- Paid time off and sick leave as required by law.
- Flexible working schedule.
- Unlimited opportunities for growth.