SIEM/Splunk Engineer - TS/SCI Cleared

Piper Companies

Newington (VA)

On-site

USD 165,000 - 190,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive Benefits
Flexible schedule
Growth opportunities

Job summary

Zachary Piper Solutions is seeking a Senior SIEM/Splunk Engineer to join a Federal Program in Newington, VA, onsite five days per week. The engineer will design, implement, tune, and maintain Splunk Enterprise and ES to support enterprise security monitoring, threat detection, and incident response.

The role requires 5–10+ years with Splunk, clustering/high availability, CIM mapping, and SOAR; you will build detections, dashboards, playbooks, and collaborate with SOC to strengthen operations.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field or equivalent experience.
  • 5–10+ years hands-on experience with Splunk Enterprise and Splunk ES.
  • Experience designing and supporting enterprise-scale Splunk with clustering and high availability.
  • Strong Splunk architecture, SPL development, dashboards, CIM mapping, and search optimization.
  • Experience with Splunk SOAR (Phantom) and security automation workflows.
  • Knowledge of SIEM operations, MITRE ATT&CK, threat detection, and incident response.
  • Experience integrating security tech including cloud platforms (AWS/Azure/GCP) and IAM.
  • Proficiency in Linux/Unix, scripting, and automation (Git, Ansible).
  • Splunk certifications and TS/SCI clearance preferred.

Responsibilities

  • Architect, deploy, administer, and optimize Splunk Enterprise and ES.
  • Design scalable, highly available Splunk infrastructure with clustering and data ingestion.
  • Manage data onboarding, CIM compliance, and integrations across sources.
  • Develop correlation searches, dashboards, models, and MITRE-aligned detections.
  • Implement SOAR playbooks and automated response workflows.
  • Perform health checks, capacity planning, and platform modernization efforts.
  • Establish governance, RBAC, and security hardening for Splunk environments.
  • Automate deployments and admin tasks with Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC to improve detection and incident response workflows.
  • Maintain architecture docs and standard operating procedures.

Skills

Splunk Enterprise
Splunk ES
SPL development
Data models CIM
SOAR (Phantom)
Python
Bash
PowerShell
Git
Ansible
Linux/Unix
Scripting
MITRE ATT&CK
SecurityClearance

Education

Bachelor's degree in Cybersecurity/CS

Tools

AWS
Azure
GCP
IAM
RBAC

Job description

Zachary Piper Solutions is seeking an Senior SIEM/Splunk to join a Federal Program located in Newington, VA, onsite 5 days per week. The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response.

Responsibilities of the SIEM/Splunk Engineer:
  • Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.
  • Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
  • Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
  • Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
  • Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
  • Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
  • Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
  • Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
  • Maintain architecture documentation, operational procedures, playbooks, and technical standards.
Qualifications of the SIEM/Splunk Engineer:
  • Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
  • 5–10+ years of hands‑on experience with Splunk Enterprise and Splunk ES
  • Experience designing, deploying, and supporting enterprise‑scale Splunk environments with clustering, high availability, and large‑volume data ingestion.
  • Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
  • Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
  • Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
  • Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
  • Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
  • Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
  • Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
  • Active TS/SCI Security Clearance
Compensation for the SIEM/Splunk Engineer:
  • Salary Range: $165,000+ *flexible based on experience*
  • Comprehensive Benefits: Medical, Dental, Vision, PTO, and Sick Leave as required by law
  • Flexible working schedule
  • Unlimited opportunities for growth

Key Words: SIEM, splunk, bash, python, powershell, aws, azure, gcp, mitre, soar, phantom, tcp, udp, upgrades, migrations, edr, fw, ids, ips, cloud logs, cim, mapping, iam, ssl, splunk enterpise, splunk es, spl, configure, manage, engineer, federal, cleared, army, navy, air force, defense, clearance, government, models, dashboards, data models, soc, sme, playbooks, architecture, scripts, scripting, incident response

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM/Splunk Engineer - TS/SCI Cleared
SIEM/Splunk Engineer - TS/SCI Cleared

Zachary Piper Solutions • Newington (VA)

On-site
USD 165,000 - 210,000
Comprehensive benefits
Flexible schedule
Unlimited growth opportunities
SIEM Engineer
SIEM Engineer

Zachary Piper Solutions • Newington (VA), Northern (KY)

On-site
USD 120,000 - 180,000
SIEM Engineer
SIEM Engineer

Piper Companies • Newington (VA)

On-site
USD 120,000 - 180,000
Full benefits package
Tuition reimbursement
Senior Splunk Engineer
Senior Splunk Engineer

Piper Companies • Newington (VA)

On-site
USD 175,000 - 195,000
PTO
Medical
Dental
+2
Senior SIEM/Splunk Engineer - Enterprise Security & SOAR
Senior SIEM/Splunk Engineer - Enterprise Security & SOAR

Zachary Piper Solutions • Newington (VA)

On-site
USD 165,000 - 210,000
Comprehensive benefits
Flexible schedule
Unlimited growth opportunities
Senior Splunk SIEM Engineer - ES & SOAR Expert
Senior Splunk SIEM Engineer - ES & SOAR Expert

Piper Companies • Newington (VA)

On-site
USD 165,000 - 190,000
Comprehensive Benefits
Flexible schedule
Growth opportunities
Senior Splunk Enterprise Security Engineer (TS/SCI)
Senior Splunk Enterprise Security Engineer (TS/SCI)

Piper Companies • Newington (VA)

On-site
USD 120,000 - 180,000
Full benefits package
Tuition reimbursement
Senior Splunk Engineer - On-site SIEM & Threat Detection
Senior Splunk Engineer - On-site SIEM & Threat Detection

Piper Companies • Newington (VA)

On-site
USD 175,000 - 195,000
PTO
Medical
Dental
+2
Splunk / SOC Engineer
Splunk / SOC Engineer

Piper Companies • North Carolina

Hybrid
USD 100,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+2
SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000