SIEM/Splunk Engineer - TS/SCI Cleared

Zachary Piper Solutions

Newington, Northern (VA, KY)

On-site

USD 140,000 - 190,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision, PTO, and Sick
Flexible working schedule
Unlimited opportunities for growth

Job summary

Zachary Piper Solutions in Newington, VA is seeking a Senior SIEM/Splunk Engineer for a Federal Program onsite five days a week. The role focuses on designing, implementing, tuning, and maintaining Splunk Enterprise and Splunk Enterprise Security to support threat detection and incident response.

Responsibilities include deploying Splunk, writing SPL, integrating data sources, building dashboards and playbooks, and collaborating with SOC teams to strengthen security operations for

Qualifications

  • Bachelor's degree in a relevant field or equivalent experience.
  • 5-10+ years hands-on Splunk Enterprise and ES experience.
  • Experience designing, deploying, and supporting enterprise Splunk with clustering and large-volume ingestion.

Responsibilities

  • Architect, deploy, administer, and optimize Splunk Enterprise and ES.
  • Design scalable, highly available Splunk infra with clustering and large ingestion.
  • Onboard data, CIM mapping, and integrations across sources.
  • Develop correlation searches, dashboards, and MITRE-aligned detection content.
  • Implement SOAR playbooks, automated responses, and tool integrations.
  • Perform health checks, tuning, upgrades, and modernization initiatives.
  • Maintain governance, RBAC, security hardening, and compliance standards.
  • Automate tasks with Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC/IR teams to improve detection and investigation workflows.
  • Maintain architecture docs, procedures, playbooks, and standards.

Skills

Splunk SPL development
Security monitoring
Incident response
Threat detection
Linux/Unix administration
Scripting

Education

Bachelor's degree in Cybersecurity, Computer Science, IT, or related field

Tools

Splunk Enterprise
Splunk ES
Splunk SOAR (Phantom)
Git
Ansible
Python
Bash
PowerShell
AWS
Azure
GCP

Job description

Zachary Piper Solutions is seeking an Senior SIEM/Splunk to join a Federal Program located in Newington, VA, onsite 5 days per week. The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response.

Responsibilities of the SIEM/Splunk Engineer:
  • Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.
  • Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
  • Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
  • Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
  • Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
  • Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
  • Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
  • Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
  • Maintain architecture documentation, operational procedures, playbooks, and technical standards.
Qualifications of the SIEM/Splunk Engineer:
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
  • 5-10+ years of hands-on experience with Splunk Enterprise and Splunk ES
  • Experience designing, deploying, and supporting enterprise-scale Splunk environments with clustering, high availability, and large-volume data ingestion.
  • Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
  • Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
  • Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
  • Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
  • Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
  • Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
  • Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
  • Active TS/SCI Security Clearance
Compensation for the SIEM/Splunk Engineer:
  • Salary Range: $165,000+ *flexible based on experience*
  • Comprehensive Benefits: Medical, Dental, Vision, PTO, and Sick Leave as required by law
  • Flexible working schedule
  • Unlimited opportunities for growth

#LI-CJ2

#LI-ONSITE

Key Words: SIEM, splunk, bash, python, powershell, aws, azure, gcp, mitre, soar, phantom, tcp, udp, upgrades, migrations, edr, fw, ids, ips, cloud logs, cim, mapping, iam, ssl, splunk enterpise, splunk es, spl, configure, manage, engineer, federal, cleared, army, navy, air force, defense, clearance, government, models, dashboards, data models, soc, sme, playbooks, architecture, scripts, scripting, incident response

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk / SOC Engineer
Splunk / SOC Engineer

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Senior Splunk ES SIEM Engineer – Onsite VA
Senior Splunk ES SIEM Engineer – Onsite VA

Zachary Piper Solutions • Newington (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Medical, Dental, Vision, PTO, and Sick
Flexible working schedule
Unlimited opportunities for growth
SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000
SIEM Engineer
SIEM Engineer

Zachary Piper Solutions • Fulton (MD)

Hybrid
USD 115,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+1
Splunk Engineer
Splunk Engineer

Piper Companies • Durham (NC)

On-site
USD 150,000 - 170,000
Comprehensive benefits package
401(k)
PTO
+1
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Splunk Engineer/Architect
Splunk Engineer/Architect

Piper Companies • Morrisville (NC)

On-site
USD 140,000 - 180,000
Comprehensive benefits
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Linux SIEM System Engineer New Springfield, VA
Linux SIEM System Engineer New Springfield, VA

D2 Consulting • Springfield (VA), Northern (KY)

Hybrid
USD 135,000 - 145,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • Chesapeake (VA)

On-site
USD 110,000 - 160,000
Free Platinum-Level Medical/Dental/Vis
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4