Splunk Administrator / SIEM Analyst

Spatial Front, Inc.

United States

Hybrid

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Spatial Front, Inc. seeks a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log ingestion, analytics, and incident response in a DISA-domain environment. You will operate Splunk and SIEM platforms, onboard logs, and prepare analytics for OCI environments.

The role requires hands-on SIEM administration, security analytics, incident response support, and scripting across Splunk, Elastic, and other analytics platforms, with on-site/hybrid work in Crystal City, VA.

Qualifications

  • Must be a U.S. citizen with an active Secret Clearance.
  • Bachelor’s degree or equivalent operational experience in a related field.
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms.
  • Active CompTIA Security+ (IAT Level II compliant).
  • Experience administering Splunk in an enterprise environment.
  • Experience with SIEM operations, monitoring, and analytics.
  • Knowledge of incident response processes and security event investigation.
  • Ability to support log ingestion, parsing, normalization, and onboarding.
  • Experience scripting or automating tasks within SIEM or analytics platforms.
  • Hands-on experience with Splunk, Elastic, and other SIEM/analytics platforms.
  • Ability to work Day or Swing shift: 0800–1600 or 1600–0000.
  • Experience operating in a DISA-domain or similarly controlled enterprise environment.

Responsibilities

  • Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
  • Configure, monitor, and troubleshoot log ingestion pipelines from servers and applications.
  • Ensure reliable onboarding, normalization, and availability of security and operational logs.
  • Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response activities through log analysis and event correlation.
  • Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
  • Support analytics and logging requirements for OCI readiness/preparation.
  • Work within a DISA-domain environment and coordinate with security, infrastructure, and application teams.
  • Support monitoring and analysis for WAF, identity/access management, OHS/OAM, and WebLogic.
  • Create scripts and automation to improve SIEM administration and data onboarding.
  • Validate that data sources are properly integrated into SIEM tools.
  • Document configurations, data flows, standard procedures, and issues.

Skills

Splunk
SIEM administration
Incident response
Scripting
Log ingestion
Analytics platforms
WAF
OHS/OAM
WebLogic
DISA-domain
OCI readiness
Elastic

Education

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science

Tools

Elastic
Splunk

Job description

All Jobs > Splunk Administrator / SIEM Analyst

We are seeking a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log ingestion, analytics, and incident response activities within a DISA-domain environment. The selected candidate will operate and administer Splunk and related SIEM/analytics platforms, support server and platform log onboarding, and help prepare analytics capabilities for OCI environments.

This role requires hands-on experience with SIEM administration, security analytics, incident response support, and scripting/automation across tools such as Splunk, Elastic, and other analytics platforms. Experience with WAF, identity systems such as OHS/OAM, and WebLogic is highly desired. PeopleSoft experience is not required, but candidates should understand logging, monitoring, and analytics relevant to enterprise application environments.

Location

Crystal City, VA - On-Site/Hybrid

Work Schedule

Must be available to support either:

  • Day Shift: 0800–1600
  • Swing Shift: 1600–0000
Key Responsibilities
  • Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
  • Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms.
  • Ensure reliable onboarding, normalization, and availability of security and operational logs.
  • Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response (IR) activities through log analysis, event correlation, and investigative data support.
  • Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
  • Support analytics and logging requirements associated with OCI readiness/preparation.
  • Work within a DISA-domain environment and coordinate with stakeholders across security, infrastructure, and application teams.
  • Support monitoring and analysis for technologies including WAF, identity/access management, OHS/OAM, and WebLogic.
  • Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting.
  • Validate that server, application, and platform data sources are properly integrated into SIEM tools.
  • Document configurations, data flows, standard procedures, and operational issues.
Requirements
  • Must be a U.S. Citizen with an active Secret Clearance
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent operational experience)
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms.
  • Certifications: Active CompTIA Security+ (IAT Level II compliant).
  • Experience administering Splunk in an enterprise environment.
  • Experience with SIEM operations, monitoring, and analytics.
  • Working knowledge of incident response processes and security event investigation.
  • Ability to support log ingestion, parsing, normalization, and platform/server onboarding.
  • Experience scripting or automating tasks within SIEM or analytics platforms.
  • Hands-on experience with one or more of the following: Splunk, Elastic, other SIEM/analytics platforms.
  • Ability to work Day or Swing shift: 0800–1600 or 1600–0000.
  • Experience operating in a DISA-domain or similarly controlled enterprise environment.
  • Strong troubleshooting, analytical, and documentation skills.
Desired Qualifications
  • Experience with Web Application Firewalls (WAF).
  • Experience with identity and access management systems, including OHS/OAM.
  • Experience supporting or monitoring WebLogic environments.
  • Familiarity with OCI logging, monitoring, or analytics preparation.
  • Understanding of logging and analytics for enterprise application platforms.
  • Experience with PeopleSoft is a plus, but not required.
Preferred Skills
  • SIEM content development, correlation rule tuning, and dashboard creation.
  • Scripting with tools/languages used for automation and data handling in SIEM environments.
  • Cross-team coordination with security, system administration, and application support teams.
  • Ability to quickly identify gaps in log coverage and recommend remediation.
Additional Information:
  • All candidates will be subject to a complete background check to include, but not limited to Criminal History, Education Verification, Professional Certification Verification, Verification of Previous Employment and Credit History.
  • Public Trust background investigations can take approximately four to eight weeks and requires fingerprinting.
Other Information:
  • For information on SFI's benefits please visit http://www.spatialfront.com/pages/career.html
  • This is a full-time W2 position.
  • Please no agencies, third parties, or corp-to-corp.
  • Spatial Front Inc. is an Equal-opportunity Employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
  • Spatial Front Inc. participates in E-Verify.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk SIEM Engineer — Day or Swing (On-Site)
Senior Splunk SIEM Engineer — Day or Swing (On-Site)

Spatial Front, Inc. • United States

Hybrid
USD 110,000 - 150,000
Splunk / SOC Engineer
Splunk / SOC Engineer

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Maryland

On-site
USD 131,000 - 237,000
Competitive benefits
Paid Time Off
11 paid Holidays
+4
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • North Carolina

On-site
USD 150,000 - 160,000