SonicJobs Logo
Left arrow iconBack to search

Splunk Engineer

Fuse Engineering LLC
Posted 6 months ago, valid for a month
Location

Fort Meade, MD, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Splunk Engineer role involves designing, implementing, optimizing, and maintaining enterprise logging and security analytics solutions.
  • Candidates must have at least 5 years of experience in Splunk Enterprise architecture and administration, along with a TS/SCI w/ Polygraph Clearance.
  • Key responsibilities include maintaining operational availability of Splunk environments, developing custom dashboards, and integrating various data sources.
  • The position offers a salary of approximately $120,000 to $150,000 per year, depending on experience and qualifications.
  • The role also requires skills in Linux systems administration, scripting, and compliance reporting.

Description

 

The Splunk Engineer is responsible for the design, implementation, optimization, and sustainment of enterprise logging, monitoring, and security analytics solutions. This role ensures Splunk environments meet availability, performance, compliance, and audit requirements .


Key Responsibilities

  • Architect, deploy, and maintain enterprise Splunk environments, including indexers, search heads, forwarders, and multi-region architectures.
     
  • Design, develop, and sustain custom Splunk dashboards and analytics supporting:
     
    • Security events, audit data, and user activity monitoring (UAM)
       
    • STE/STN compliance, vulnerability and compliance scans
       
    • Network/system observable events by SSP
       
    • Containerized application events by namespace
       
    • Mission metrics, outage tracking, and system/network utilization
       
  • Ensure Splunk dashboards and logging infrastructure maintain =93% operational availability monthly.
     
  • Develop and maintain dashboards for authentication events, privileged access, account management, role escalation, and container security events.
     
  • Integrate data from NetFlow/sFlow, Syslog, Cribl, Nagios, HP NNMi, HPNA, vulnerability scanners, and compliance tools.
     
  • Perform Splunk scaling, performance tuning, data onboarding, and index management.
     
  • Maintain log retention policies ensuring:
     
    • 30 days online searchable logs
       
    • 5 years, 11 months offline retention with restore capability
       
  • Provide Tier-4 support, including vendor escalation and coordination with Splunk engineering.
     
  • Advise architects and security accreditors on Splunk security configurations and audit capabilities.
     
  • Develop automation, parsing, and enrichment logic to reduce false positives and enhance alert fidelity.

Requirements

TS/SCI w/ Polygraph Clearance Required


 

Required Skills

  • Splunk Enterprise architecture and administration
     
  • Security logging, SIEM design, and compliance reporting
     
  • Linux systems administration
     
  • Data onboarding (Syslog, NetFlow, API ingestion)
     
  • Scripting (Python, Bash, SPL)
     





Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.