Splunk Administrator (Level 3)

G2IT, LLC.

Suitland (MD)

On-site

USD 120,000 - 180,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

G2IT is seeking an experienced Splunk Administrator (Level 3) to support enterprise cybersecurity, monitoring, and data analytics environments. The candidate will have hands-on Splunk admin experience, develop SPL queries, dashboards, and alerts, and support RMF and CIM compliance in DoD/IC contexts.

Required are TS clearance eligibility, 10+ years in LAN/WAN across Windows/Unix, 6+ years in Splunk, and proficiency with Python, AWS, and RMF.

Qualifications

  • Active TS clearance with TS/SCI eligibility
  • 10+ years LAN/WAN in Windows and Unix/Linux environments
  • 8+ years CND experience
  • 6+ years Splunk administration and optimization
  • Expert Splunk Enterprise & apps (ES, SOAR, UEBA, ITSI)
  • Experience with Splunk Add-ons, Apps, TAs, and Universal Forwarders

Responsibilities

  • Install, configure, administer, maintain and optimize Splunk environments
  • Support Splunk Enterprise and ES/SOAR/UEBA/ITSI
  • Develop SPL queries, dashboards, reports, alerts
  • Perform log ingestion, parsing, normalization, analysis
  • Maintain CIM compliance and data mapping
  • Automate tasks with Python scripting
  • Support AWS and RHEL environments
  • Communicate complex cybersecurity issues to stakeholders

Skills

Splunk administration
SPL queries
Python scripting
RMF compliance
Technical documentation
Cybersecurity briefing
Strong communication

Education

Bachelor's degree in CS/IT/IA
Master's degree preferred
15+ years experience alternative to degree

Tools

Splunk Enterprise
AWS
RHEL/Windows
SQL
Python

Job description

G2IT is seeking an experienced Splunk Administrator (Level 3) to support enterprise cybersecurity, monitoring, and data analytics environments. The ideal candidate will have extensive hands-on experience administering and optimizing Splunk environments, supporting Cyber Network Defense (CND) operations, and working within DoD or Intelligence Community environments.

Key Responsibilities
  • Install, integrate, configure, administer, maintain, monitor, troubleshoot, and optimize Splunk environments.
  • Support Splunk Enterprise and advanced applications, including Enterprise Security (ES), SOAR, UEBA, and IT Service Intelligence (ITSI).
  • Install and manage Splunk Technical Add‑ons (TAs), Apps, and Universal Forwarders.
  • Develop SPL queries, dashboards, reports, alerts, and other monitoring capabilities.
  • Perform log management, ingestion, parsing, normalization, and analysis.
  • Create REGEX parsing and XML presentations of log data.
  • Maintain Splunk Common Information Model (CIM) compliance and perform automated and manual data mapping.
  • Utilize Python scripting to automate Linux and Splunk administration tasks.
  • Work with Splunk DB Connect, SQL, and database integrations to collect and analyze log data.
  • Create, install, and maintain encryption keys used to secure communication channels.
  • Perform Risk Management Framework (RMF) functions associated with Splunk environments.
  • Support AWS resources and Red Hat Enterprise Linux environments.
  • Troubleshoot LAN/WAN, networking protocols, ports, services, file systems, and Windows/Unix/Linux infrastructure.
  • Develop technical documentation, SOPs, best practices, presentations, and cybersecurity guidance.
  • Support System/Software Development Life Cycle (SDLC) processes.
  • Communicate complex cybersecurity and technical issues to management, mission stakeholders, and customers.
Required Qualifications
  • Must hold an active Top Secret (TS) security clearance and be eligible for TS/SCI access.
  • 10+ years of professional experience with LAN/WAN technologies, networking protocols, file systems, ports, services, and commands within Windows and Unix/Linux environments.
  • 8+ years of concentrated experience within the Cyber Network Defense (CND) discipline.
  • 6+ years of professional hands-on experience with Splunk administration, integration, configuration, maintenance, and optimization.
  • Expert-level knowledge of Splunk Enterprise and Splunk applications, including ES, SOAR, UEBA, and ITSI.
  • Extensive experience with Splunk Add‑ons, Apps, Technical Add‑ons (TAs), and Universal Forwarders.
  • Strong experience creating SPL queries, dashboards, reports, and alerts.
  • Experience with REGEX parsing and XML presentation of log data.
  • Experience using Python to automate Linux and Splunk administrative tasks.
  • Experience with Splunk DB Connect, SQL, and database log collection.
  • Experience with Splunk Common Information Model (CIM) compliance and data mapping.
  • Experience creating and managing encryption keys for secure communications.
  • Experience administering and managing AWS and Red Hat Enterprise Linux environments.
  • Significant experience supporting RMF functions and cybersecurity compliance.
  • Strong knowledge of Federal, DoD, Intelligence Community, and industry cybersecurity standards.
  • Significant experience with SDLC processes and developing technical documentation, manuals, SOPs, and best practices.
  • Strong analytical, organizational, problem-solving, documentation, and briefing skills.
  • Ability to prioritize and complete tasks with minimal direction in a high-pressure environment.
  • Ability to communicate effectively with technical teams, customers, mission stakeholders, and all levels of management.
Certification Requirements
  • Prior to starting, candidates must possess an applicable DoD cybersecurity certification that satisfies the contract's CSSP Infrastructure Support requirements.
Education
  • Bachelor's degree in Computer Science, Information Technology, Information Assurance, or a related field is desired.
  • Master's degree is preferred.
  • Candidates without a degree should have 15+ years of relevant professional experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk Admin (TS/SCI) – CND & Enterprise Security
Senior Splunk Admin (TS/SCI) – CND & Enterprise Security

G2IT, LLC. • Suitland (MD)

On-site
USD 120,000 - 180,000
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Cyber Security Analyst
Cyber Security Analyst

Makoa • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • Chesapeake (VA)

On-site
USD 110,000 - 160,000
Free Platinum-Level Medical/Dental/Vis
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates Inc. • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Senior Principal Cyber Security Engineer
Senior Principal Cyber Security Engineer

International Association of Plumbing and Mechanical Officials (IAPMO) • Chantilly (VA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate • Richmond (VA)

On-site
USD 120,000 - 180,000