A complete application in a minute — tailored resume and cover letter, ready to send.
Booz Allen Hamilton in McLean, VA is seeking an Observability Pipeline Engineer to own the telemetry feeding logging, monitoring, and security analytics across commercial and government environments.
You will build and evolve the telemetry pipeline using Cribl and Splunk, automate source onboarding as code (GitOps), and apply AI tooling to parser/schema work to reduce manual effort while detecting failures before downstream systems are impacted.
Join a culture of empowerment and connectivity.
Learn the skills you need to accelerate your career.
Discover benefits that your life and work.
Build mission-ready tech that protects the nation.
Are you looking for an opportunity to combine deep technical skill with big picture thinking to make an impact on the systems people depend on every day? You understand that observability starts with the data, and that every dashboard, alert, and investigation is only as good as the tele met ry underneath it. As an observability pipeline engineer on our team, you'll own the tele met ry that feeds logging, monitoring, and security analytics across commer cia l and accredited government environments.
Your customers will t rus t you not only to build and operate the pipeline in Cribl and Splunk, but to evolve it — delivering source onboarding as code, applying AI to the parser and schema work that has traditionally consumed days, and building a pipeline that detects its own failures before anyone downstream is affected.
On our team, you'll broaden your skills in OpenTele met ry and tele met ry standards. This role builds the pipeline itself. The work sits upstream of the dashboards, alerts, and searches everyone else uses, and its quality determines theirs. The ideal candidate comes from a data engineering, log platform, SIEM, or observability infrastructure background and has run high-volume pipelines in production under real cost and retention constraints.
What You'll Work On:
Build and evolve the tele met ry pipeline that carries logs, met rics, and events across every accredited environment, including sources, parsing, enrichment, normalization, routing, and destinations.
Engineer the Splunk log platform from distributed architecture and index design through data onboarding and search performance.
Automate source onboarding end to end so that adding a data source is a pull request rather than a ticket, with all pipeline configuration managed as code under GitOps.
Apply AI tooling to parser generation, schema mapping, and normalization, collapsing work that used to take days.
Instrument the pipeline to detect its own failures, including silent sources, schema drift, and volume and cost anomalies, before anyone downstream notices.
Design reduction, cardinality, retention,