SonicJobs Logo
Left arrow iconBack to search

SIEM Administrator/Engineer

SAIC
Posted 11 days ago, valid for a month
Location

Washington, DC, US

Salary

Competitive

Contract type

Full Time

By applying, a SAIC account will be created for you. SAIC's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • SAIC is looking for a SIEM Administrator/Engineer to enhance cybersecurity operations and modernize security monitoring capabilities.
  • The role requires a minimum of three years of experience and involves hands-on administration of the Splunk environment while transitioning to Elastic Security.
  • Candidates should possess strong SIEM administration skills and demonstrate the ability to troubleshoot and improve the SIEM infrastructure independently.
  • This hybrid position mandates at least three on-site days per week in Washington, DC, and offers a salary of approximately $90,000 to $130,000 per year, depending on experience.
  • SAIC is a leading mission integrator with a focus on technology innovation, serving various sectors including defense and intelligence.

SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency's security monitoring and analytics capabilities. This position will provide hands-on administration of the organization's existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security.

The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment.

***This hybrid role requires a minimum of three on-site days per week in Washington, DC.***

Responsibilities

  • Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security.
  • Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases.
  • Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs.
  • Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS).
  • Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search.
  • Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable.
  • Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting.
  • Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity.
  • Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities.
  • Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions.
  • Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes.
  • Maintain technical documentation and take ownership of assigned technical issues and projects through resolution.

SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a SAIC account will be created for you. SAIC's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.