Splunk Administrator / SIEM Analyst

Spatial Front, Inc

Crystal City (TX)

Hybrid

USD 100,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Spatial Front, Inc. in Crystal City, VA (On-Site/Hybrid) seeks a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log onboarding, analytics, and incident response.

You will administer Splunk and related analytics platforms, configure ingestion pipelines, and develop dashboards and alerts to improve detection and response. Ideal candidates have 5+ years in log management and SIEM, and hands-on Splunk experience in enterprise settings.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent operational experience).
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms.
  • Active CompTIA Security+ (IAT Level II compliant).
  • Experience administering Splunk in an enterprise environment.
  • Experience with SIEM operations, monitoring, and analytics.
  • Working knowledge of incident response processes and security event investigation.
  • Ability to support log ingestion, parsing, normalization, and platform/server onboarding.
  • Experience scripting or automating tasks within SIEM or analytics platforms.
  • Hands-on experience with one or more of the following: Splunk, Elastic, other SIEM/analytics platforms.
  • Ability to work Day or Swing shift: 0800-1600 or 1600-0000.
  • Experience operating in a DISA-domain or similarly controlled enterprise environment.
  • Strong troubleshooting, analytical, and documentation skills.

Responsibilities

  • Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
  • Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms.
  • Ensure reliable onboarding, normalization, and availability of security and operational logs.
  • Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response (IR) activities through log analysis, event correlation, and investigative data support.
  • Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
  • Support analytics and logging requirements associated with OCI readiness/preparation.
  • Work within a DISA-domain environment and coordinate with stakeholders across security, infrastructure, and application teams.
  • Support monitoring and analysis for technologies including WAF, identity/access management, OHS/OAM, and WebLogic.
  • Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting.
  • Validate that server, application, and platform data sources are properly integrated into SIEM tools.
  • Document configurations, data flows, standard procedures, and operational issues.

Skills

Splunk administration
SIEM analytics
Incident response
Log ingestion
Scripting/Automation
Elastic
WAF
OHS/OAM
WebLogic
DISA-domain experience

Education

Bachelor's degree

Tools

Splunk
Elastic
Other SIEM platforms

Job description

Description

We are seeking a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log ingestion, analytics, and incident response activities within a DISA-domain environment. The selected candidate will operate and administer Splunk and related SIEM/analytics platforms, support server and platform log onboarding, and help prepare analytics capabilities for OCI environments. This role requires hands-on experience with SIEM administration, security analytics, incident response support, and scripting/automation across tools such as Splunk, Elastic, and other analytics platforms. Experience with WAF, identity systems such as OHS/OAM, and WebLogic is highly desired. PeopleSoft experience is not required, but candidates should understand logging, monitoring, and analytics relevant to enterprise application environments.

Location

Crystal City, VA - On-Site/Hybrid

Work Schedule

Must be available to support either:

  • Day Shift: 0800-1600
  • Swing Shift: 1600-0000
Key Responsibilities
  • Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
  • Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms.
  • Ensure reliable onboarding, normalization, and availability of security and operational logs.
  • Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response (IR) activities through log analysis, event correlation, and investigative data support.
  • Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
  • Support analytics and logging requirements associated with OCI readiness/preparation.
  • Work within a DISA-domain environment and coordinate with stakeholders across security, infrastructure, and application teams.
  • Support monitoring and analysis for technologies including WAF, identity/access management, OHS/OAM, and WebLogic.
  • Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting.
  • Validate that server, application, and platform data sources are properly integrated into SIEM tools.
  • Document configurations, data flows, standard procedures, and operational issues.
Requirements
  • Must be a U.S. Citizen with an active Secret Clearance
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent operational experience)
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms.
  • Certifications: Active CompTIA Security+ (IAT Level II compliant).
  • Experience administering Splunk in an enterprise environment.
  • Experience with SIEM operations, monitoring, and analytics.
  • Working knowledge of incident response processes and security event investigation.
  • Ability to support log ingestion, parsing, normalization, and platform/server onboarding.
  • Experience scripting or automating tasks within SIEM or analytics platforms.
  • Hands-on experience with one or more of the following: Splunk, Elastic, other SIEM/analytics platforms.
  • Ability to work Day or Swing shift: 0800-1600 or 1600-0000.
  • Experience operating in a DISA-domain or similarly controlled enterprise environment.
  • Strong troubleshooting, analytical, and documentation skills.
Desired Qualifications
  • Experience with Web Application Firewalls (WAF).
  • Experience with identity and access management systems, including OHS/OAM.
  • Experience supporting or monitoring WebLogic environments.
  • Familiarity with OCI logging, monitoring, or analytics preparation.
  • Understanding of logging and analytics for enterprise application platforms.
  • Experience with PeopleSoft is a plus, but not required.
Preferred Skills
  • SIEM content development, correlation rule tuning, and dashboard creation.
  • Scripting with tools/languages used for automation and data handling in SIEM environments.
  • Cross-team coordination with security, system administration, and application support teams.
  • Ability to quickly identify gaps in log coverage and recommend remediation.
Additional Information
  • All candidates will be subject to a complete background check to include, but not limited to Criminal History, Education Verification, Professional Certification Verification, Verification of Previous Employment and Credit History.
  • Public Trust background investigations can take approximately four to eight weeks and requires fingerprinting.
Other Information
  • For information on SFI's benefits please visit http://www.spatialfront.com/pages/career.html
  • This is a full-time W2 position.
  • Spatial Front Inc. is an Equal-opportunity Employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
  • Spatial Front Inc. participates in E-Verify.
Salary Description

$100,000-$150,000

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Administrator / SIEM Analyst
Splunk Administrator / SIEM Analyst

Spatial Front, Inc. • United States

Hybrid
USD 110,000 - 150,000
Splunk Administrator / SIEM Analyst
Splunk Administrator / SIEM Analyst

Jobtailor • Virginia (MN)

On-site
USD 120,000 - 170,000
Senior Splunk & SIEM Analyst – DISA Environment (Hybrid)
Senior Splunk & SIEM Analyst – DISA Environment (Hybrid)

Spatial Front, Inc • Crystal City (TX)

Hybrid
USD 100,000 - 150,000
Senior Splunk SIEM Engineer — Day or Swing (On-Site)
Senior Splunk SIEM Engineer — Day or Swing (On-Site)

Spatial Front, Inc. • United States

Hybrid
USD 110,000 - 150,000
Splunk Analyst
Splunk Analyst

FedTec • Woodlawn (MD)

On-site
USD 95,000 - 125,000
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Annapolis (MD)

On-site
USD 131,000 - 237,000
Paid Time Off
11 paid Holidays
401K with 6% match
+2
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000