Why This Role Stands Out
This Splunk Engineer role offers a fantastic opportunity to architect and build a critical security platform, leveraging cutting-edge technologies like ITSI, UEBA, and Enterprise Security Premier. You'll thrive here if you possess deep Splunk expertise, a knack for complex data engineering, and a passion for developing robust, scalable solutions in a dynamic environment. Apply now to make a significant impact and grow your career.
Quick Overview
Job Description
Splunk Engineer 2
Remote (must be local to DC area incase customers need onsite support)
Must be US citizen with TS/SCI Eligibility Role Summary: A hands-on senior Splunk consultant who can architect and build the platform, engineer the data layer, and stand-up Enterprise Security Premier, ITSI, and UEBA, while producing client facing documentation / cross train / manage scoping.
Must Have Skills: o Experience deploying Splunk ITSI, UEBA, ES Premier o Splunk Enterprise 10.x architecture: multisite indexer clustering and search head clustering o SmartStore on Azure Hot Blob, plus Azure Archive Blob (GRS) for immutable backup o Index design and retention strategy (per-index, 30-month hot tier, set at build) o Deployment server, forwarder management, and Universal Forwarders at scale o Monitoring Console, RBAC, TLS/certificates, Linux administration, syslog (rsyslog/syslog-ng) o Data onboarding and CIM normalization (hard prerequisite for ES/UEBA) o SplunkBase TA deployment and data model design/acceleration o ITSI: install, KPIs/services/entities, content packs, event analytics (correlation searches, NEAPs, glass tables) o Enterprise Security Premier: install/config, Assets & Identities against Microsoft Entra ID/AD, use-case library, threat intel, Risk-Based Alerting o ES-embedded UEBA: configuration, identity/asset enrichment, 4-week baseline and tuning o Expert SPL and private app/TA development (Simple XML and Dashboard Studio) o Clear technical writing (gap analyses, mapping documents, readiness summaries) Nice to Have Skills: o Splunk certifications (Core Consultant, ES Admin, ITSI Admin, Enterprise Architect) o Cribl experience (excluded now, likely future scope) o Azure and Microsoft Entra ID administration depth o DISA STIG/OS hardening and NIST SP 800-53 / RMF / ATO literacy o Federal delivery at large scale (~10,000 users)
Similar jobs
- HA
Engineering Technician C
NewHarris Corporation
Mason, OH🇺🇸On-siteYesterdayCADSolidWorksEngineering - IN
Workload Placement Engineer - Mexico - Contract
NewInfiCare
United States🇺🇸HybridYesterdayEngineering - ID
Ontology Engineer - Finance/Accounting
NewInfo Dinamica Inc
Hartford, CT🇺🇸On-siteYesterdayEngineering - LT
Director of Engineering
Ledgent Technology
Sunnyvale, CA🇺🇸$185k - $225k/yrOn-site4 weeks agoCFDFEAEngineering - TI
Career Accelerator Program - Process Development Engineer - MS/PhD - Lehi
NewTexas Instruments Incorporated
Lehi, UT🇺🇸HybridYesterdayEngineering - HA
Senior Associate, Electrical Engineer 1
NewHarris Corporation
Greenville, TX🇺🇸HybridYesterdayCADElectrical DesignEngineering