Senior SIEM Engineer - Splunk

Quantum Sky

Washington (District of Columbia)

On-site

USD 145,000 - 155,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Quantum Sky is seeking a Senior SIEM Engineer to own and evolve the Splunk deployment—architecture, data onboarding, CIM normalization, and platform health. You will drive detection engineering within Splunk ES and mentor mid-level engineers, aligning Splunk capabilities with leadership's security strategy.

The role requires on-site work in Washington, DC, with five days/week in the environment, core hours 8am–4pm, and a Top Secret clearance with SCI eligibility.

Qualifications

  • Bachelor's degree required; experience and education equivalents considered.
  • 8 years of general work experience with 6 years in security operations or detection engineering, with Splunk ownership.
  • Advanced proficiency in SPL, including complex correlation searches and data models.
  • Deep Splunk architecture knowledge (indexer/search head clustering, forwarders), and Splunk ES if deployed.
  • Strong understanding of MITRE ATT&CK, cyber kill chain, threat modeling.
  • Experience designing detection strategies within Splunk, not just individual searches.
  • Strong scripting/automation (Python, PowerShell) and SOAR integration familiarity.
  • Experience with cloud security monitoring (AWS/Azure/GCP) and cloud add-ons.
  • Incident response leadership experience.
  • Familiarity with industry compliance frameworks; relevant Splunk certifications preferred.

Responsibilities

  • Design and own the Splunk architecture, including clustering, forwarders, and storage strategy.
  • Lead detection engineering strategy within Splunk ES based on threat intel and risk assessments.
  • Establish standards for data onboarding, CIM normalization, and field extraction quality.
  • Drive Splunk upgrades, app/add-on management, and integrations with security tools.
  • Optimize search performance and licensing costs at scale.
  • Mentor mid-level SIEM engineers and SOC analysts in SPL and use case design.
  • Serve as escalation point for complex investigations and incidents.
  • Evaluate new Splunk apps and architectural changes.
  • Own Splunk metrics and reporting for leadership (detection coverage, MTTD, performance).
  • Lead threat hunting using SPL, data models, and Splunk pivot/statistical functions.
  • Ensure configurations meet PCI-DSS, HIPAA, SOC 2, NIST compliance.
  • Represent SIEM in security architecture and incident response planning.

Skills

Splunk architecture
Detection engineering
SPL mastery
Python scripting
Cloud log monitoring
Threat modeling

Education

Bachelor's Degree

Tools

Splunk ES
SOAR platforms
AWS/Azure/GCP

Job description

Description

Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operateswith autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy.Theseniorengineeristhe escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents.

Responsibilities

  • Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (includingSmartStorewhere applicable) strategy
  • Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage
  • Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance
  • Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems)
  • Optimizesearch performance and indexing strategy to manage license usage and infrastructure cost at scale
  • Mentor andprovidetechnical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices
  • Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunkexpertise
  • Evaluate and recommend new Splunk apps, premiumsolutions,or architectural changes
  • Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency)
  • Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions
  • Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST)
  • Represent the SIEM/detection function in cross-functional security architecture and incident response planning
Qualifications

Required:

  • Bachelor's Degreerequired(experience and education equivalents are considered and can be substituted for aBachelor's Degree.
  • 8 years of general work experience with 6 years relevant “functional” experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments
  • Advancedproficiencyin SPL, including complex correlation searches, data models, and search optimization for large-scale environments
  • Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed
  • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling
  • Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches
  • Strong scripting/automation skills (Python, PowerShell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use)
  • Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons
  • Track recordof leading or significantly contributing to incident response investigations
  • Familiarity with compliance frameworks relevant to the organization's industry
  • Relevant certifications preferred: Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP

Desired:

  • Experience with Splunk in aVMwareESXi, vCenter virtual infrastructure
  • Experience or working knowledge with similar SIEM tools

Clearance:

  • An active Top Secret clearance with SCI eligibility is required.

Location and Schedule:

  • This position is onsite at the customer location in Washington, DC. The environment requires onsite support five days per week, with some flexibility in scheduling based on program and customer requirements. Core business hours are 8am-4pm.
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $145,000-$155,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk SIEM Architect & Detection Lead
Senior Splunk SIEM Architect & Detection Lead

Quantum Sky • Washington

On-site
USD 145,000 - 155,000
Cloud Security Engineer
Cloud Security Engineer

Quantum Sky • Washington

Hybrid
USD 140,000 - 150,000
Health/Dental/Vision
SOC Analyst (Tier 2)
SOC Analyst (Tier 2)

Tyto Athene • Washington

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
ISSM / Security Automation Engineer
ISSM / Security Automation Engineer

Tyto Athene, LLC • Northern (KY)

Hybrid
USD 175,000 - 190,000
Health/Dental/Vision
401(k) match
Paid Time Off
Senior Splunk Engineer
Senior Splunk Engineer

Zachary Piper Solutions • Newington (VA), Northern (KY)

Hybrid
USD 175,000 - 195,000
PTO
Paid Holidays
Medical insurance
+5
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Quantico Base (VA)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Enterprise ITSM & Continual Service Improvement (CSI) Lead
Enterprise ITSM & Continual Service Improvement (CSI) Lead

Quantum Sky • Arlington (VA)

On-site
USD 150,000 - 210,000
Splunk / SOC Engineer
Splunk / SOC Engineer

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Senior Splunk Architect
Senior Splunk Architect

Qmulos • Washington

On-site
USD 90,000 - 130,000
Offensive Cyber/AI-ML Engineer
Offensive Cyber/AI-ML Engineer

Quantum Sky • Reston (VA)

On-site
USD 150,000 - 225,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4