Lead Splunk ES Admin | TS/SCI | SOC Ops - Suitland

Leidos Inc

Suitland (MD)

On-site

USD 108,000 - 195,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos is seeking a Splunk Enterprise and Enterprise Security Administrator to maintain the NAVINTEL SIEM environment, engineer detection logic, develop dashboards, and support SOC operations in Suitland, MD.

The role requires an Active TS/SCI clearance and extensive experience with Splunk Enterprise/ES, CIM mapping, and Linux administration. You will onboard data sources, collaborate on incident response, and produce operational reports to strengthen defensive postures.

Qualifications

  • Bachelor's degree in CS, IT, IA or related area with 8+ years of experience or a Master's degree with 6+ years of experience.
  • Active TS/SCI security clearance.
  • Demonstrated experience supporting Computer Network Defense (CND) operations and technologies.
  • 6+ years professional experience in Splunk, Splunk Add-ons and Apps, and Splunk TA and Universal Forwarder installation, integration, configuration, administration, maintenance, and performance of RMF functions.
  • Deep experience with Splunk Enterprise/ES, search processing language (SPL), CIM mapping, dashboards, and Linux administration.
  • Experience supporting SOC workflows and SIEM tuning.

Responsibilities

  • Administer Splunk Enterprise, Enterprise Security, CIM compliance, correlation searches, RBAs, dashboards, and data models.
  • Onboard new data sources and ensure quality, parsing, and normalization.
  • Support incident response, threat hunting, detection engineering, and content governance.
  • Produce operational reports, posture summaries, dashboards, and detection documentation.

Skills

Security clearance TS/SCI
Splunk administration
CIM mapping & dashboards
SPL & data models
Linux administration
SOC workflows
SIEM tuning
Incident response & threat hunting

Education

Bachelor's degree in CS/IT/IA
Master's degree in a related field

Tools

Splunk Add-ons & Apps
Splunk TA & Universal Forwarder

Job description

Leidos is seeking a Splunk Enterprise and Enterprise Security Administrator to maintain the NAVINTEL SIEM environment, engineer detection logic, develop dashboards, and support SOC operations in Suitland, MD.

The role requires an Active TS/SCI clearance and extensive experience with Splunk Enterprise/ES, CIM mapping, and Linux administration. You will onboard data sources, collaborate on incident response, and produce operational reports to strengthen defensive postures.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk ES Admin — TS/SCI SIEM & SOC
Senior Splunk ES Admin — TS/SCI SIEM & SOC

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk Enterprise & Enterprise Security Admin (TS/SCI)
Splunk Enterprise & Enterprise Security Admin (TS/SCI)

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
TS/SCI Splunk Administrator – Security Analytics Expert
TS/SCI Splunk Administrator – Security Analytics Expert

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
TS/SCI Splunk Administrator - Defensive Cyber Operations
TS/SCI Splunk Administrator - Defensive Cyber Operations

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk Enterprise and Enterprise Security Administrator
Splunk Enterprise and Enterprise Security Administrator

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk SOAR Engineer | TS/SCI Clearance
Splunk SOAR Engineer | TS/SCI Clearance

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Senior Splunk SOAR Administrator TS/SCI
Senior Splunk SOAR Administrator TS/SCI

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk Enterprise and Enterprise Security Administrator
Splunk Enterprise and Enterprise Security Administrator

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Senior Splunk SOAR Administrator - TS/SCI, SIEM Expert
Senior Splunk SOAR Administrator - TS/SCI, SIEM Expert

G2IT, LLC. • Suitland (MD)

On-site
USD 130,000 - 190,000
Splunk Enterprise and Enterprise Security Administrator
Splunk Enterprise and Enterprise Security Administrator

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000