Cybersecurity Specialist Splunk Engineer

SAIC

United States

Remote

USD 100,000 - 140,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote work

Job summary

SAIC invites applications for a Cybersecurity Specialist, Splunk Engineer. This role can be remote within the United States and supports the Enterprise Security Operations Center by maintaining Splunk and related SIEM tools, developing detections, and building dashboards.

The candidate will onboard data sources, optimize correlations, and collaborate with Azure and AWS environments while mentoring ESOC staff and ensuring secure, reliable operations.

Qualifications

  • Bachelor’s degree in a related field with 5+ years of cybersecurity/analysis experience, or advanced degree with 3+ years.
  • Experience administering and engineering Splunk, with relevant certifications in Splunk Core Admin.
  • Must obtain Splunk Core Certified Admin within 3 months, Azure Fundamentals within 6 months, AWS Practitioner within 9 months.
  • US Citizenship and ability to work flexible hours including on-call rotations.

Responsibilities

  • Administer, configure, and maintain Splunk (cloud and on‑prem) and SIEM tools.
  • Develop, audit, and optimize correlation rules; craft new detections with ESOC.
  • Build dashboards, reports, alerts, and visualizations; tune SPL queries.
  • Onboard data sources (syslog, HEC, forwarders, APIs) and manage data sources.
  • Support deployment servers/forwarders and maintain cloud integrations (Azure/AWS).
  • Develop scripts/integrations with security tools (Python, Bash, PowerShell).
  • Collaborate with stakeholders, mentor ESOC members, and ensure compliance.

Skills

Splunk administration
Cybersecurity operations
Scripting (Python/Bash)
Cloud security concepts

Education

Bachelor’s Degree
Master’s Degree

Tools

Splunk
Azure
AWS

Job description

Cybersecurity Specialist Splunk Engineer

Job ID: 2617557
Location: Remote Work, TN, United States
Date Posted: Oct 2, 2026
Category: Cyber
Subcategory: Cybersecurity Spec
Schedule: Full-Time
Shift: Day Job
Travel: No
Minimum Clearance Required: None
Clearance Level Must Be Able to Obtain: None
Potential for Remote Work: Remote
Benefits: Click here

SAIC has an opening for a Cybersecurity Specialist, Splunk Engineer. For the right candidate, this position may be remote anywhere in the United States.

This position is responsible for duties around supporting the tools and technologies that are owned and operated by the Enterprise Security Operations Center. The Splunk Engineer will support other organizations within the company delivering solutions for data-driven challenges that enable the company.

The individual should be knowledgeable on a number of security technologies, have a solid understanding of information security and networking and experience interacting with customers. Will be able to engage on tasks independently, document and communicate work efforts and provide technical support.

The position will be responsible for maintaining and tuning the signatures, interfaces, and technical processes to ensure the tools are operational and meet the requirements of Enterprise Security Operations.

Job Duties:

  • Administer, install, configure, and maintain Splunk (cloud and on prem) and other SIEM/log management tools.
  • Develop, audit, and optimize correlation rules; collaborate with ESOC to create new detections.
  • Build and maintain dashboards, reports, alerts, and visualizations.
  • Create and optimize SPL queries; manage knowledge objects (field extractions, tags, lookups, macros).
  • Onboard and manage data sources (syslog, HEC, forwarders, APIs).
  • Manage deployment servers and forwarders.
  • Maintain inputs, reporting, and alerting across Azure and AWS environments.
  • Work at the system level to improve performance and propose platform enhancements.
  • Develop scripts and integrations with security tools (Python, Bash, PowerShell).
  • Work with workflow automation tools to orchestrate processes with ServiceNow and other security/infrastructure platforms.
  • Use regular expressions (regex) for parsing, extraction, and automation.
  • Document procedures for data ingestion and maintain access controls for compliance.
  • Create and implement configuration standards, policies, and procedures for improved operations.
  • Develop program metrics to measure monitoring effectiveness.
  • Resolve incidents and issues; integrate changes with established change management processes.
  • Train and mentor ESOC members on SIEM capabilities and best practices.
  • Interface with analysts and business stakeholders to ensure tools, dashboards, and applications meet requirements.
  • Communicate effectively with teams and clients.
  • Work across Linux and Windows platforms.
  • Apply an understanding of networking technologies, workflows, and IT reporting

Qualifications

Required Education and Experience:

  • Bachelor’s Degree and 5+ years cybersecurity operation related experience or software analyst/programming related experience, or master’s degree and 3+ years related experience. An additional 4 years of experience may be considered in lieu of a degree.
  • Demonstrated experience administering and engineering Splunk.
  • Must obtain the Splunk Core Certified Admin certification within the first 3 months of employment.
  • Must obtain the Azure AZ-900: Microsoft Azure Fundamentals certification within 6 months of employment.
  • Must obtain the AWS Cloud Practitioner certification within 9 months of employment.
  • Availability to work flexible hours and be available for on call during rotations.
  • Must be a US Citizen.

Target salary range: $100,001 - $140,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

SAIC accepts applications on an ongoing basis and there is no deadline.

SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit newsroom.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Splunk Engineer — Cybersecurity Specialist
Remote Splunk Engineer — Cybersecurity Specialist

SAIC • United States

Remote
USD 100,000 - 140,000
Remote work
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates, Inc • Richmond (VA)

On-site
USD 110,000 - 150,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates Inc. • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

ZealHire Inc. • Richmond (VA), Northern (KY)

Hybrid
USD 110,000 - 190,000
Splunk / SOC Engineer - 174235 - 174717 - 175230
Splunk / SOC Engineer - 174235 - 174717 - 175230

ZP Group • North Carolina

Hybrid
USD 100,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Cyber Security Engineer (Splunk)
Senior Cyber Security Engineer (Splunk)

CACI International Inc • Chantilly (VA)

On-site
USD 103,800 - 218,100
Comprehensive healthcare
Flexible time off
Continuing education support
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Cybersecurity Jobs • Richmond (VA)

On-site
USD 115,000 - 150,000