Splunk Engineer

Onyx Point, Inc.

Illinois

Remote

USD 78,000 - 250,000

Full time

32 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health coverage
401(k) plan
Paid time off
Dental, Vision
Professional development
Remote work options
Technology allowance
Bonus opportunities

Job summary

Onyx Point, Inc. is seeking a Senior Splunk Administrator to design, implement, and maintain a hardened Splunk environment on RHEL 8, with RSA integration and cross-platform support for Windows and Linux.

The role requires a TS/SCI clearance, extensive Splunk experience in distributed deployments, and a strong focus on security and automation. You will lead architecture design, deployment, and ongoing optimization while collaborating with security, network, and system teams to ensure resilient

Qualifications

  • Active DoD TS/SCI clearance required.
  • 12+ years in system administration, networks, or cybersecurity.
  • 8+ years with Linux/Windows administration.
  • 5+ years administering Splunk in distributed deployments.
  • Splunk Certified Architect certification required.

Responsibilities

  • Design, implement, and maintain Splunk environments (forwarders, indexers, search heads, deployment servers).
  • Install, configure, and secure Splunk on RHEL 8 and Windows systems.
  • Harden Splunk on RHEL 8 to meet security standards.
  • Integrate Splunk with RSA for secure auth across environments.
  • Monitor health, performance, and capacity; perform routine maintenance.
  • Troubleshoot performance, ingestion, and search issues; optimize queries.
  • Create architecture diagrams, installation guides, and runbooks.
  • Collaborate with security, network, and system admins for seamless integration.

Skills

Security clearance TS/SCI
Splunk administration
RHEL 8 administration
RSA integration
Windows integration
Networking fundamentals
Documentation
Communication
Splunk CIM onboarding
Scripting inputs & modular inputs

Education

Bachelor’s degree in Computer Science or related field

Tools

Splunk Enterprise
RSA authentication

Job description

TS/ w/ SCI and US Citizenship
Job Description

We have an IMMEDIATE NEED a highly skilled Senior Splunk Administrator to join our team and take charge of designing, implementing, and maintaining our Splunk environment. The ideal candidate will possess a deep understanding of Splunk architecture and its various components including forwarders, indexers, and web interfaces. Moreover, proficiency in setting up Splunk on a Red Hat Enterprise Linux 8 (RHEL 8) system that is hardened is essential for this role. Additionally, the candidate should demonstrate expertise in integrating Splunk with RSA and effectively configuring it to work seamlessly with both RHEL 8 and Windows environments.

Responsibilities
  • Design and Architecture: Design, implement, and maintain Splunk environments including forwarders, indexers, search heads, and deployment servers.
  • Installation and Configuration: Install, configure, and integrate Splunk and its components on RHEL 8 systems, ensuring optimal performance, scalability, and security.
  • Security Hardening: Harden the Splunk environment on RHEL 8 systems to meet security compliance standards and best practices.
  • Integration: Integrate Splunk with RSA for secure authentication and authorization across the environment.
  • Monitoring and Maintenance: Monitor Splunk infrastructure health, performance, and capacity; perform routine maintenance tasks to ensure uninterrupted service.
  • Troubleshooting: Troubleshoot issues related to Splunk infrastructure, including performance bottlenecks, data ingestion problems, and search optimization.
  • Documentation: Create and maintain comprehensive documentation including architecture diagrams, installation guides, and troubleshooting procedures.
  • Collaboration: Collaborate with cross-functional teams including security, network, and system administrators to ensure seamless integration of Splunk within the IT infrastructure.
Core Qualifications
  • Current DoD TS/SCI security clearance.
  • Bachelor’s degree in Computer Science, Engineering, or a related field and a minimum of 12+ years of experience in system administration, database administration, network engineering, software engineering, or software development, with a concentration in Cybersecurity
  • Eight (8) years of experience with Linux and Windows system administration or an advanced understanding of operating systems and common operating environments
  • Five (5) years of experience administering Splunk in distributed deployments
  • Excellent written and verbal communication skills, ability to work closely with multiple customers, manage expectations and track engagement scope
  • Proficient at data on-boarding activities including routing, parsing, and normalizing events to the Splunk Common Information Model (CIM)
  • Proficient onboarding data using Splunk add-ons for Windows, Linux, and common third-party devices and applications
  • Experience onboarding data into Splunk via forwarder, scripted inputs, and modular inputs from a variety of sources
  • Experience with Splunk performing systems administration, including performing installation, configuration, monitoring system performance and availability, upgrades, and troubleshooting
  • General knowledge of networking and security troubleshooting (firewalls, routing, NAT, etc.)
  • Splunk implementation and troubleshooting experience
  • Proficiency developing log ingestion and aggregation strategies per Splunk best practices
  • Perform integration activities to configure, connect, and pull data with 3rd party software APIs
  • Ability to autonomously prioritize and successfully deliver results
  • Must have a Splunk Certified Architect certification
  • Must have a DoD 8570 IAT Level II (or Level III) certification (e.g. Sec+ CE)
  • All candidates must be US CITIZENS to be considered for the position
Preferred Qualifications
  • Experience configuring and maintaining the tool in a multi-tenant environment
  • Experience troubleshooting RSA and Windows integration.
  • Experience troubleshooting RSA integration with Linux through PAM
  • Experience troubleshooting Cisco ISE AAA
  • Experience in troubleshooting LDAPS
  • Experience with application integration with Radiant One through LDAPS
Compensation

We are committed to providing fair and competitive compensation. The salary range for this position is $78,000 to $250,000 per year. This range reflects the compensation offered across the locations where we hire. The exact salary will be determined based on the candidate's work location, specific role, skill set, and level of expertise.

Benefits
  • Health Coverage: Medical, dental, and vision insurance
  • Additional Insurance: Basic Life/AD&D, Voluntary Life/AD&D, Short and Long-Term Disability, Accident, Critical Illness, Hospitalization Indemnity, and Pet Insurance
  • Retirement Plan: 401(k) plan with company match
  • Paid Time Off: Generous PTO, paid holidays, parental leave, and more
  • Wellness: Access to wellness programs and mental health support
  • Professional Development: Opportunities for growth, including tuition reimbursement
  • Flexible work arrangements, including remote work options
  • Flexible Spending Accounts (FSAs)
  • Employee referral programs
  • Bonus opportunities
  • Technology allowance
  • A diverse, inclusive, and supportive workplace culture
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Splunk Engineer
Splunk Engineer

Onyx Point, Inc. • Shiloh (IL)

Remote
USD 78,000 - 250,000
Health insurance
401(k) plan
Paid time off
+2
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Splunk Engineer
Splunk Engineer

SpaceX • Redmond (WA)

On-site
USD 130,000 - 200,000
Stock options
Discretionary bonuses
Medical, vision, and dental coverage
+4
Splunk Cyber Security SME
Splunk Cyber Security SME

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 160,000
Splunk Engineer
Splunk Engineer

Peraton • Herndon (VA)

On-site
USD 112,000 - 179,000
Heavily subsidized benefits coverage
25 days PTO accrued annually
Attractive bonus plan
Splunk Software Engineer (SF)
Splunk Software Engineer (SF)

The Kenjya-Trusant Group , LLC • Maryland

On-site
USD 125,000 - 250,000
Medical, Vision & Dental Insurance
Paid Time-Off
Company Paid Holidays
+2
Sr. Splunk Engineer
Sr. Splunk Engineer

ECS Corporate Services • Fairfax (VA)

Remote
USD 140,000 - 190,000
TS/SCI Splunk Engineer — Mission-Critical Analytics
TS/SCI Splunk Engineer — Mission-Critical Analytics

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Splunk Engineer
Splunk Engineer

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Splunk Engineer - TS/ SCI security clearance
Splunk Engineer - TS/ SCI security clearance

CDW • North Dakota

On-site
USD 190,000 - 240,000