Haystack
← Back to Jobs
Temporary/Casual
Engineering
CS

Splunk Engineer 2 with Security Clearance

Catapult StaffingArlington, VA🇺🇸United StatesPosted 4 Sept 2026

Why This Role Stands Out

This Splunk Engineer role offers a fantastic opportunity to architect and build a critical security platform, leveraging cutting-edge technologies like ITSI, UEBA, and Enterprise Security Premier. You'll thrive here if you possess deep Splunk expertise, a knack for complex data engineering, and a passion for developing robust, scalable solutions in a dynamic environment. Apply now to make a significant impact and grow your career.

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
On Site
Location
Arlington, VA, United States
Posted
Yesterday

Job Description

Splunk Engineer 2
Remote (must be local to DC area incase customers need onsite support)
Must be US citizen with TS/SCI Eligibility Role Summary: A hands-on senior Splunk consultant who can architect and build the platform, engineer the data layer, and stand-up Enterprise Security Premier, ITSI, and UEBA, while producing client facing documentation / cross train / manage scoping.

Must Have Skills: o Experience deploying Splunk ITSI, UEBA, ES Premier o Splunk Enterprise 10.x architecture: multisite indexer clustering and search head clustering o SmartStore on Azure Hot Blob, plus Azure Archive Blob (GRS) for immutable backup o Index design and retention strategy (per-index, 30-month hot tier, set at build) o Deployment server, forwarder management, and Universal Forwarders at scale o Monitoring Console, RBAC, TLS/certificates, Linux administration, syslog (rsyslog/syslog-ng) o Data onboarding and CIM normalization (hard prerequisite for ES/UEBA) o SplunkBase TA deployment and data model design/acceleration o ITSI: install, KPIs/services/entities, content packs, event analytics (correlation searches, NEAPs, glass tables) o Enterprise Security Premier: install/config, Assets & Identities against Microsoft Entra ID/AD, use-case library, threat intel, Risk-Based Alerting o ES-embedded UEBA: configuration, identity/asset enrichment, 4-week baseline and tuning o Expert SPL and private app/TA development (Simple XML and Dashboard Studio) o Clear technical writing (gap analyses, mapping documents, readiness summaries) Nice to Have Skills: o Splunk certifications (Core Consultant, ES Admin, ITSI Admin, Enterprise Architect) o Cribl experience (excluded now, likely future scope) o Azure and Microsoft Entra ID administration depth o DISA STIG/OS hardening and NIST SP 800-53 / RMF / ATO literacy o Federal delivery at large scale (~10,000 users)

Similar jobs