SIEM Administrator/Engineer

Saic

Washington (District of Columbia)

Hybrid

USD 80,000 - 120,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and modernize monitoring and analytics capabilities. This role will provide hands-on administration of Splunk while helping transition security monitoring, log analytics, and detection capabilities to Elastic Security.

The ideal candidate will grow into a broader engineering role, independently troubleshooting production SIEM and logging infrastructure while demonstrating ownership and initiative to

Qualifications

  • Bachelor's degree in a related technical field (or 4 years of experience in lieu of degree).
  • 5+ years of IT/cybersecurity experience.
  • Ability to obtain and maintain a public trust (U.S. Citizenship or Green Card).
  • 3+ years of hands-on SIEM administration in enterprise environments.
  • Hands-on Splunk Enterprise experience: SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and troubleshooting.
  • Experience onboarding and troubleshooting enterprise log sources end-to-end (telemetry flow).
  • Solid SQL skills for data analysis, troubleshooting, validation, or reporting.
  • Familiarity with Elastic Stack (Elasticsearch, Kibana) and ECS.
  • Understanding of enterprise logging concepts (collection, parsing, enrichment, indexing, retention).
  • Strong Linux/Windows skills, networking, and common protocols.

Responsibilities

  • Administer, maintain, monitor, and troubleshoot Splunk Enterprise and support Elastic Security modernization.
  • Assist migration from Splunk to Elastic, including data sources, searches, dashboards, and alerts.
  • Configure and troubleshoot enterprise log ingestion pipelines across diverse sources.
  • Onboard new data sources and ensure telemetry is parsed, normalized, and searchable.
  • Develop and optimize SIEM searches, dashboards, and detections using SPL and Elastic queries.
  • Use SQL and other queries to analyze data for investigations and reporting.
  • Monitor SIEM health, performance, storage, and capacity; optimize accordingly.
  • Collaborate with security analysts to tune detections and improve monitoring.

Skills

SIEM administration
SPL
KQL / Elastic query languages
SQL querying
Linux / Windows administration
Threat hunting / detection engineering
Automation scripting (Python/PowerShel

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related technical discipline

Tools

Splunk Enterprise
Elastic Stack / Elastic Security
Elastic Agent / Fleet
Elasticsearch
Kibana
Logstash
Beats

Job description

Description

SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency's security monitoring and analytics capabilities. This position will provide hands-on administration of the organization's existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security.

The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment.

***This hybrid role requires a minimum of three on-site days per week in Washington, DC.***

Responsibilities
  • Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security.
  • Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases.
  • Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs.
  • Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS).
  • Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search.
  • Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable.
  • Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting.
  • Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity.
  • Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities.
  • Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions.
  • Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes.
  • Maintain technical documentation and take ownership of assigned technical issues and projects through resolution.
Qualifications
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree)
  • 5+ years experience relevant IT/cybersecurity experience.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments.
  • Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting.
  • Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search.
  • Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting.
  • Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise.
  • Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality.
  • Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, HTTP/HTTPS, TLS, and syslog.
  • Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms.
  • Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions.
  • Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages.
  • Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams.
Preferred Qualifications
  • Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash.
  • Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages.
  • Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration.
  • Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments.
  • Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK.
  • Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies.
  • Experience working in or closely supporting a Security Operations Center (SOC).
  • Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications.

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Socket.dev • Richmond (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

electro soft • Richmond (OH)

On-site
USD 150,000 - 160,000
EOE/Veterans/Disabled
Sr. Splunk / SIEM Engineer (TS Required)
Sr. Splunk / SIEM Engineer (TS Required)

augustschell • Alexandria (VA)

Hybrid
USD 100,000 - 130,000
Hybrid SIEM Engineer: Splunk to Elastic (DC On-Site)
Hybrid SIEM Engineer: Splunk to Elastic (DC On-Site)

Saic • Washington

Hybrid
USD 80,000 - 120,000
Security Information Event Manager (SIEM) Administrator
Security Information Event Manager (SIEM) Administrator

Castalia Systems • Waipahu (HI)

On-site
USD 120,000 - 124,000
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000