Splunk Engineer

CACI

United States

On-site

USD 113,000 - 238,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CAC I is seeking a Splunk Engineer with 8+ years of experience to manage a Splunk Platform and develop ITSI-based apps. You will build dashboards, automate maintenance, and onboard new data sources for government customers.

The role requires TS/SCI with Poly clearance, Scrum/Agile collaboration, and strong Linux security and cybersecurity compliance knowledge. Experience with AWS/Azure and Splunk certifications is highly valued.

Qualifications

  • BA/BS degree required; 8+ years IT experience if no degree
  • 8+ years experience supporting IT systems
  • 4+ years implementing and operating Splunk (universal and heavy forwarders, search heads, deployment server, indexes)
  • Splunk Enterprise, IT Service Intelligence, Log Management experience
  • Knowledge of RMF/IA security standards
  • Excellent problem solving and collaboration skills
  • Splunk IT Service Intelligence (ITSI) and Splunk Certified Admin certifications preferred
  • Experience with Linux security and cybersecurity compliance

Responsibilities

  • Design scripts to automate Splunk maintenance and alerting
  • Develop dashboards and reports for business-critical insights
  • Create scalable security architectures with standard integrations
  • Onboard new data sources and ensure data quality
  • Support cloud deployments (AWS and Azure) and cyber compliance tasks
  • Collaborate with product owners and IT teams to resolve issues
  • Provide training and support to IT staff on Splunk usage
  • Develop integration scripts for enterprise security services
  • Document configurations and procedures

Skills

Splunk
ITSI
RMF/IA
Linux security
Communication
Collaboration
Training IT staff
Scripting

Education

BA/BS degree
AA/AS with 10 years experience

Tools

Python
Perl
JavaScript
AWS
Azure

Job description

Job Title: Splunk Engineer

Job Category: Engineering

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI with Polygraph

Employee Type: Regular

Percentage of Travel Required: None

Type of Travel: None

The Opportunity:

CACI is seeking a highly motivated Splunk Engineer that has 8+ years of experience managing a Splunk Platform, creating Splunk applications, and using IT Service Intelligence (ITSI). The Splunk engineer will build applications to help manage, search, analyze, and visualize data. The role includes troubleshooting and performing Splunk application development following a Scrum Agile approach. The role also includes examining the existing environment for deficiencies and onboarding new data sources.

Responsibilities:
  • Design core scripts to automate Splunk maintenance and alerting tasks
  • Develop dashboards and reports to display business-critical information
  • Develop and maintain dashboards, reports, and alerts to ensure efficient monitoring and management of IT systems
  • Engage with Product Owners to align platform capabilities with evolving business needs
  • Create scalable, flexible security architectures using standards-based integrations
  • Assist in developing policies for the secure operation of Splunk infrastructure
  • Support cloud-based deployment and sustainment (AWS and Azure)
  • Conduct software integration testing and cybersecurity compliance tasks
  • Automate processes and develop efficiencies alongside development and install teams
  • Maintain infrastructure for integration, cyber compliance, and network administration
  • Support both UNIX/Linux and Windows-based systems
  • Collaborate with IT teams to identify, troubleshoot, and resolve IT issues using Splunk
  • Document configurations, changes, and troubleshooting procedures.
  • Support new operational needs by integrating Splunk with other enterprise security services as required by government customers
  • Collaborate with government customers to understand their specific security service integration requirements
  • Develop and maintain integration scripts and configurations for various enterprise security services
  • Onboard new data sources into the Splunk environment, ensuring proper indexing, data normalization, and data quality
  • Develop and maintain scripts and configurations for onboarding new data sources
  • Ensure seamless data flow from new data sources into Splunk
  • Troubleshoot and resolve issues related to onboarding new data sources
Qualifications:

Required:

  • TS/SCI Clearance with Counterintelligence Polygraph
  • BA/BS degree and 8 years of experience. In lieu of a bachelor’s degree 10 years of experience if AA/AS, or 12 additional years of experience with HS diploma
  • 8+ years of experience and demonstrated knowledge supporting IT Systems
  • 4+ years of experience implementing and operating Splunk systems to include universal and heavy forwarders, search heads, deployment server, and indexes
  • Design, develop, and implement new features for Splunk products
  • Provide training and support to IT staff on Splunk usage and best practices
  • Proven experience in designing, implementing, and maintaining Splunk solutions including, but not limited to: Splunk Enterprise, Splunk IT Service Intelligence, Splunk Log Management
  • Knowledge of Linux security best practices
  • Knowledge of cybersecurity compliance including RMF and IA standards
  • Excellent problem-solving and analytical skills
  • Service-oriented mindset
  • Strong communication and collaboration skills
  • At least one Splunk Certification: Splunk Certified for Splunk IT Service Intelligence (ITSI), Splunk Certified Administrator (SCA)

Desired:

  • Experience integrating Splunk with ServiceNow to enable automated incident management, problem management, and change management workflows
  • Knowledge of security compliance and ATO (Authority to Operate) support
  • Preferred knowledge of FISMA (Federal Information Security Management Act) requirements
  • Current Security+ or DOD 8570 IAT Level II Certification
  • AWS or Azure Certification
  • ITIL v4 Certification
  • Strong understanding of IT operations, security, and business intelligence
  • Good team player with a strong willingness to help others
  • Experience scripting in the following preferred: Python, Perl, and JavaScript in relation to Splunk Apps/Add-ons, SQL for querying structured data, Knowledge of XML and JSON for data handling, Splunk Search Processing Language (SPL) for data analysis in Splunk
What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

Pay Range

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is:

$113,200 - $237,800

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Engineer
Splunk Engineer

CACI International Inc • McLean (VA)

On-site
USD 131,000 - 290,000
Comprehensive healthcare
Financial benefits
Continuing education support
+1
Splunk Engineer
Splunk Engineer

CACI International Inc. • McLean (VA)

On-site
USD 113,000 - 238,000
Splunk Software Engineer-TS/SCI with Poly
Splunk Software Engineer-TS/SCI with Poly

CACI • United States

On-site
USD 79,000 - 163,000
Healthcare benefits
Flexible time off
Learning resources
Splunk Software Engineer
Splunk Software Engineer

CACI International Inc • Fort Meade (MD)

On-site
USD 94,000 - 199,000
Comprehensive healthcare
Wellness benefits
Retirement options
+2
Splunk Software Engineer-TS/SCI with Poly
Splunk Software Engineer-TS/SCI with Poly

CACI International Inc • Columbia (MD)

On-site
USD 79,000 - 163,000
Healthcare benefits
Flexible time off
Learning and development opportunities
Senior Cyber Security Engineer (Splunk)
Senior Cyber Security Engineer (Splunk)

CACI • United States

On-site
USD 104,000 - 218,000
Senior Cyber Security Engineer (Splunk)
Senior Cyber Security Engineer (Splunk)

CACI International Inc • Chantilly (VA)

On-site
USD 103,000 - 219,000
Comprehensive healthcare
Flexible time off
Continuing education support
Splunk Software Engineer Fort Meade, MD, US
Splunk Software Engineer Fort Meade, MD, US

CACI International Inc. • Fort Meade (MD)

On-site
USD 94,000 - 199,000
Healthcare
Flexible time off
Retirement benefits
+1
Senior Cloud DevOps Engineer
Senior Cloud DevOps Engineer

CACI International Inc • San Antonio (TX)

On-site
USD 86,000 - 180,000
Senior Cloud DevOps Engineer
Senior Cloud DevOps Engineer

CACI International Inc. • San Antonio (TX)

On-site
USD 86,000 - 180,000