Splunk Engineer

CACI

McLean (VA)

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CACI is seeking a highly experienced Splunk Engineer to manage the Splunk Platform, develop ITSI dashboards, and integrate data sources across a secure enterprise environment. The role requires 8+ years of hands-on Splunk experience, strong scripting skills, and familiarity with RMF/IA and cybersecurity compliance.

You will collaborate with government customers, support cloud deployments (AWS/Azure), and drive automation for monitoring, incident response, and data visualization.

Qualifications

  • 8+ years of Splunk experience in enterprise settings.
  • Experience with ITSI, dashboards, and data visualization.
  • Knowledge of RMF/IA and cybersecurity compliance.
  • Experience designing and maintaining Splunk solutions including Enterprise and ITSI.

Responsibilities

  • Design core scripts to automate Splunk maintenance and alerting tasks
  • Develop dashboards and reports to display business-critical information
  • Develop and maintain dashboards, reports, and alerts for IT systems
  • Engage with Product Owners to align platform capabilities with business needs
  • Create scalable security architectures using standards-based integrations
  • Assist in policies for secure operation of Splunk infrastructure
  • Support cloud-based deployment and sustainment (AWS and Azure)
  • Automate processes and develop efficiencies with development and install teams
  • Maintain infrastructure for integration, cyber compliance, and network administration
  • Collaborate with IT teams to troubleshoot Splunk issues
  • Document configurations, changes, and troubleshooting procedures
  • Onboard new data sources into Splunk ensuring proper indexing and data quality

Skills

Splunk Platform mgmt
ITSI dashboards
Scripting (Python/PowerShell/JS)
Cloud integration
Collaboration with stakeholders

Education

BA/BS in CS/IS
AA/AS in lieu of BS

Tools

Splunk Universal Forwarders
Splunk Heavy Forwarders
Splunk Search Heads
Deployment Server
Indexes management

Job description

Job Title: Splunk Engineer

Job Category: Engineering

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI with Polygraph

Employee Type: Regular

Percentage of Travel Required: None

Type of Travel: None

The Opportunity:

CACI is seeking a highly motivated Splunk Engineer that has 8+ years of experience managing a Splunk Platform, creating Splunk applications, and using IT Service Intelligence (ITSI). The Splunk engineer will build applications to help manage, search, analyze, and visualize data. The role includes troubleshooting and performing Splunk application development following a Scrum Agile approach. The role also includes examining the existing environment for deficiencies and onboarding new data sources.

Responsibilities:
  • Design core scripts to automate Splunk maintenance and alerting tasks
  • Develop dashboards and reports to display business-critical information
  • Develop and maintain dashboards, reports, and alerts to ensure efficient monitoring and management of IT systems
  • Engage with Product Owners to align platform capabilities with evolving business needs
  • Create scalable, flexible security architectures using standards-based integrations
  • Assist in developing policies for the secure operation of Splunk infrastructure
  • Support cloud-based deployment and sustainment (AWS and Azure)
  • Conduct software integration testing and cybersecurity compliance tasks
  • Automate processes and develop efficiencies alongside development and install teams
  • Maintain infrastructure for integration, cyber compliance, and network administration
  • Support both UNIX/Linux and Windows-based systems
  • Collaborate with IT teams to identify, troubleshoot, and resolve IT issues using Splunk
  • Document configurations, changes, and troubleshooting procedures.
  • Support new operational needs by integrating Splunk with other enterprise security services as required by government customers
  • Collaborate with government customers to understand their specific security service integration requirements
  • Develop and maintain integration scripts and configurations for various enterprise security services
  • Onboard new data sources into the Splunk environment, ensuring proper indexing, data normalization, and data quality
  • Develop and maintain scripts and configurations for onboarding new data sources
  • Ensure seamless data flow from new data sources into Splunk
  • Troubleshoot and resolve issues related to onboarding new data sources
Qualifications:
  • TS/SCI Clearance with Counterintelligence Polygraph
  • BA/BS degree and 8 years of experience. In lieu of a bachelor's degree 10 years of experience if AA/AS, or 12 additional years of experience with HS diploma
  • 8+ years of experience and demonstrated knowledge supporting IT Systems
  • 4+ years of experience implementing and operating Splunk systems to include universal and heavy forwarders, search heads, deployment server, and indexes
  • Design, develop, and implement new features for Splunk products
  • Provide training and support to IT staff on Splunk usage and best practices
  • Proven experience in designing, implementing, and maintaining Splunk solutions including, but not limited to: Splunk Enterprise, Splunk IT Service Intelligence, Splunk Log Management
  • Knowledge of Linux security best practices
  • Knowledge of cybersecurity compliance including RMF and IA standards
  • Excellent problem-solving and analytical skills
  • Service-oriented mindset
  • Strong communication and collaboration skills
  • At least one Splunk Certification: Splunk Certified for Splunk IT Service Intelligence (ITSI), Splunk Certified Administrator (SCA)
Desired:
  • Experience integrating Splunk with ServiceNow to enable automated incident management, problem management, and change management workflows
  • Knowledge of security compliance and ATO (Authority to Operate) support
  • Preferred knowledge of FISMA (Federal Information Security Management Act) requirements
  • Current Security+ or DOD 8570 IAT Level II Certification
  • AWS or Azure Certification
  • ITIL v4 Certification
  • Strong understanding of IT operations, security, and business intelligence
  • Good team player with a strong willingness to help others
  • Experience scripting in the following preferred: Python, Perl, and JavaScript in relation to Splunk Apps/Add-ons, SQL for querying structured data, Knowledge of XML and JSON for data handling, Splunk Search Processing Language (SPL) for data analysis in Splunk
What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust lea

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Engineer
Splunk Engineer

CACI International Inc • McLean (VA)

On-site
USD 131,000 - 290,000
Comprehensive healthcare
Financial benefits
Continuing education support
+1
Splunk Engineer
Splunk Engineer

CACI International Inc. • McLean (VA)

On-site
USD 113,000 - 238,000
Splunk Software Engineer-TS/SCI with Poly
Splunk Software Engineer-TS/SCI with Poly

CACI International Inc • Columbia (MD)

On-site
USD 79,000 - 163,000
Healthcare benefits
Flexible time off
Learning and development opportunities
Splunk Software Engineer
Splunk Software Engineer

CACI International Inc • Fort Meade (MD)

On-site
USD 94,000 - 199,000
Comprehensive healthcare
Wellness benefits
Retirement options
+2
Splunk Software Engineer-TS/SCI with Poly
Splunk Software Engineer-TS/SCI with Poly

CACI • Columbia (MD)

On-site
USD 79,000 - 163,000
Splunk Software Engineer
Splunk Software Engineer

CACI • Fort Meade (MD)

On-site
USD 94,000 - 199,000
Healthcare
Learning resources
Flexible time off
Splunk Data Analyst
Splunk Data Analyst

CACI • Laurel (MD)

On-site
USD 104,000 - 218,000
Splunk Software Engineer Fort Meade, MD, US
Splunk Software Engineer Fort Meade, MD, US

CACI International Inc. • Fort Meade (MD)

On-site
USD 94,000 - 199,000
Healthcare
Flexible time off
Retirement benefits
+1
Senior Cyber Security Engineer (Splunk)
Senior Cyber Security Engineer (Splunk)

CACI International Inc • Chantilly (VA)

On-site
USD 103,000 - 219,000
Comprehensive healthcare
Flexible time off
Continuing education support
TS/SCI Splunk Engineer - ITSI & Data Dashboards
TS/SCI Splunk Engineer - ITSI & Data Dashboards

CACI • McLean (VA)

On-site
USD 140,000 - 190,000