Senior SIEM Engineer (Splunk)

Quantum Sky

Washington (District of Columbia)

On-site

USD 140,000 - 210,000

Full time

4 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Quantum Sky is seeking a Senior SIEM Engineer to own the architecture, strategy, and long-term health of our Splunk deployment in Washington, DC. This role leads detection engineering, data onboarding standards, and platform scalability while mentoring junior engineers.

You will partner with security leadership, drive upgrades, and ensure compliance alignments (PCI-DSS, HIPAA, SOC 2, NIST) across the environment.

Qualifications

  • Bachelor’s Degree required (experience can substitute).
  • 8+ years in security operations/detection engineering with Splunk ownership.
  • Advanced SPL proficiency and large-scale search optimization.
  • Strong scripting (Python/PowerShell) and SOAR integration familiarity.

Responsibilities

  • Design and own the Splunk architecture including indexer/search-head clustering and storage/retention strategy.
  • Lead detection engineering strategy within Splunk ES and prioritize correlation searches.
  • Establish standards for data onboarding, CIM normalization, and search performance.
  • Drive platform upgrades, app/add-on management, and integrations with security tools.
  • Mentor mid-level SIEM engineers and SOC analysts on SPL and best practices.
  • Act as escalation point for complex investigations and incidents.

Skills

SPL
Threat modeling
Incident response
Python
PowerShell
Detection engineering
Scripting & automation
MITRE ATT&CK
Cloud security monitoring

Education

Bachelor’s Degree

Tools

Splunk
Splunk ES
Splunk SOAR
VMware ESXi

Job description

Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operates with autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy. The senior engineer is the escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents.

Responsibilities
  • Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (including SmartStore where applicable) strategy
  • Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage
  • Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance
  • Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems)
  • Optimize search performance and indexing strategy to manage license usage and infrastructure cost at scale
  • Mentor and provide technical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices
  • Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunk expertise
  • Evaluate and recommend new Splunk apps, premium solutions, or architectural changes
  • Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency)
  • Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions
  • Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST)
  • Represent the SIEM/detection function in cross-functional security architecture and incident response planning
Required:
  • Bachelor’s Degree required (experience and education equivalents are considered and can be substituted for a Bachelor’s Degree.
  • 8 years of general work experience with 6 years relevant “functional” experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments
  • Advanced proficiency in SPL, including complex correlation searches, data models, and search optimization for large-scale environments
  • Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed
  • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling
  • Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches
  • Strong scripting/automation skills (Python, PowerShell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use)
  • Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons
  • Track record of leading or significantly contributing to incident response investigations
  • Familiarity with compliance frameworks relevant to the organization's industry
  • Relevant certifications preferred: Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP
  • Experience with Splunk in a VMware ESXi, vCenter virtual infrastructure
  • Experience or working knowledge with similar SIEM tools
Clearance:
  • An active Top Secret clearance with SCI eligibility is required.
Location and Schedule:
  • This position is onsite at the customer location in Washington, DC. The environment requires onsite support five days per week, with some flexibility in scheduling based on program and customer requirements. Core business hours are 8am-4pm.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM Engineer - Splunk
Senior SIEM Engineer - Splunk

Quantum Sky • Washington

On-site
USD 145,000 - 155,000
Senior Splunk SIEM Architect & Detection Lead
Senior Splunk SIEM Architect & Detection Lead

Quantum Sky • Washington

On-site
USD 145,000 - 155,000
Senior SIEM Engineer - Splunk Architect (Onsite DC)
Senior SIEM Engineer - Splunk Architect (Onsite DC)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
SIEM Engineer
SIEM Engineer

Zachary Piper Solutions • Newington (VA), Northern (KY)

On-site
USD 120,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Splunk / SOC Engineer
Splunk / SOC Engineer

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Senior Splunk Engineer
Senior Splunk Engineer

Zachary Piper Solutions • Newington (VA), Northern (KY)

Hybrid
USD 175,000 - 195,000
PTO
Paid Holidays
Medical insurance
+5
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000