Turn this role into an interview — a resume and cover letter built around what this employer wants.
Jobtailor is seeking a cybersecurity engineer to administer Splunk and SIEM analytics within a DISA-domain environment. You will develop searches, dashboards, alerts, and analytics use cases to support incident response and operations.
The role requires 5+ years in log management and SIEM, US Citizenship with an active Secret Clearance, and a Bachelor's degree (or equivalent). You will collaborate with security, infra, and application teams across shifts.
• Administer, operate, and maintain Splunk and other SIEM/analytics platforms
• Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms
• Ensure reliable onboarding, normalization, and availability of security and operational logs
• Develop and maintain searches, dashboards, alerts, reports, and analytics use cases
• Support incident response activities through log analysis, event correlation, and investigative data support
• Tune SIEM content to improve detection fidelity and reduce false positives
• Support analytics and logging requirements associated with OCI readiness/preparation
• Work within a DISA-domain environment and coordinate with security, infrastructure, and application teams
• Support monitoring and analysis for WAF, identity/access management, OHS/OAM, and WebLogic
• Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting
• Validate server, application, and platform data source integration into SIEM tools
• Document configurations, data flows, standard procedures, and operational issues
• Identify gaps in log coverage and recommend remediation
Demonstrates expertise in administering and maintaining Splunk and other SIEM platforms, with a strong focus on log management, incident response, and analytics. Proficient in scripting and automation to enhance SIEM operations and ensure data integrity.