Splunk Administrator / SIEM Analyst

Jobtailor

Virginia (MN)

On-site

USD 120,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking a cybersecurity engineer to administer Splunk and SIEM analytics within a DISA-domain environment. You will develop searches, dashboards, alerts, and analytics use cases to support incident response and operations.

The role requires 5+ years in log management and SIEM, US Citizenship with an active Secret Clearance, and a Bachelor's degree (or equivalent). You will collaborate with security, infra, and application teams across shifts.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS, or equivalent experience.
  • Active CompTIA Security+ certification.
  • 5+ years in log management and SIEM platforms.
  • US Citizenship with an active Secret Clearance.

Responsibilities

  • Administer, operate, and maintain Splunk and SIEM/analytics platforms.
  • Configure and troubleshoot log ingestion pipelines from various sources.
  • Develop searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response through log analysis and event correlation.
  • Tune SIEM content to reduce false positives and improve detection fidelity.
  • Document configurations, data flows, and procedures.
  • Identify gaps in log coverage and recommend remediation.

Skills

Analytical Skills
Problem-Solving
Communication

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
CompTIA Security+

Tools

Splunk
Elastic
WebLogic

Job description

• Administer, operate, and maintain Splunk and other SIEM/analytics platforms
• Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms
• Ensure reliable onboarding, normalization, and availability of security and operational logs
• Develop and maintain searches, dashboards, alerts, reports, and analytics use cases
• Support incident response activities through log analysis, event correlation, and investigative data support
• Tune SIEM content to improve detection fidelity and reduce false positives
• Support analytics and logging requirements associated with OCI readiness/preparation
• Work within a DISA-domain environment and coordinate with security, infrastructure, and application teams
• Support monitoring and analysis for WAF, identity/access management, OHS/OAM, and WebLogic
• Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting
• Validate server, application, and platform data source integration into SIEM tools
• Document configurations, data flows, standard procedures, and operational issues
• Identify gaps in log coverage and recommend remediation

Requirements
  • Must be a U.S. Citizen with an active Secret Clearance
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent operational experience)
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms
  • Active CompTIA Security+ (IAT Level II compliant)
  • Experience administering Splunk in an enterprise environment
  • Experience with SIEM operations, monitoring, and analytics
  • Working knowledge of incident response processes and security event investigation
  • Ability to support log ingestion, parsing, normalization, and platform/server onboarding
  • Experience scripting or automating tasks within SIEM or analytics platforms
  • Hands-on experience with Splunk, Elastic, or other SIEM/analytics platforms
  • Ability to work Day or Swing shift: 0800–1600 or 1600–0000
  • Experience operating in a DISA-domain or similarly controlled enterprise environment
  • Strong troubleshooting, analytical, and documentation skills
  • Candidates subject to a complete background check, including criminal history, education verification, professional certification verification, previous employment verification, and credit history
  • Fingerprinting required for Public Trust background investigations
Core Competencies

Demonstrates expertise in administering and maintaining Splunk and other SIEM platforms, with a strong focus on log management, incident response, and analytics. Proficient in scripting and automation to enhance SIEM operations and ensure data integrity.

Highest-signal resume keywords
  • Splunk Administration
  • SIEM Operations
  • Log Management
  • CompTIA Security+
  • Incident Response
Hard Skills
  • Log Ingestion
  • Data Normalization
  • Event Correlation
  • Dashboard Development
  • Search Development
  • Alert Configuration
  • Scripting
  • Automation
  • Troubleshooting
  • Documentation
Soft Skills
  • Analytical Skills
  • Problem-Solving
  • Communication
Certifications & Qualifications
  • CompTIA Security+
  • Active Secret Clearance
Industry Keywords
  • DISA-Domain Environment
  • Cybersecurity
  • Information Technology
  • Operational Logs
  • Security Event Investigation
Tools & Technologies
  • SIEM Platforms
  • Splunk
  • Elastic
  • WAF
  • OHS/OAM
  • WebLogic
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Administrator / SIEM Analyst
Splunk Administrator / SIEM Analyst

Spatial Front, Inc. • United States

Hybrid
USD 110,000 - 150,000
Splunk Administrator / SIEM Analyst
Splunk Administrator / SIEM Analyst

Spatial Front, Inc • Crystal City (TX)

Hybrid
USD 100,000 - 150,000
IT Security SIEM Engineer – Splunk Experience Required
IT Security SIEM Engineer – Splunk Experience Required

Jobtailor • New York (NY)

On-site
USD 120,000 - 160,000
Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Splunk Engineer-W2
Splunk Engineer-W2

System Soft Technologies • Montgomery (AL)

On-site
USD 90,000 - 120,000
Senior Splunk Engineer – TS/SCI, CI Poly
Senior Splunk Engineer – TS/SCI, CI Poly

Jobtailor • Washington

On-site
USD 145,000 - 190,000
Senior SIEM Engineer (Splunk)
Senior SIEM Engineer (Splunk)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
Engineer III – SIEM Integrations
Engineer III – SIEM Integrations

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Information Security Engineer
Information Security Engineer

LanceSoft, Inc. • Melbourne (FL)

On-site
USD 90,000 - 120,000