Splunk SOAR Engineer | TS/SCI Clearance

Leidos

Suitland (MD)

On-site

USD 108,000 - 195,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Leidos is seeking a Splunk SOAR Administrator in Suitland, MD to provide engineering, operations, and technical support for SIEM platforms supporting threat detection and incident management for the HGCC program.

You will design, deploy, and maintain SOAR playbooks, integrate with Splunk ES and ticketing systems, and ensure secure transmission of Audit.XML records. Active TS/SCI and CISSP-type certification are required.

Qualifications

  • 8+ years of engineering experience supporting Computer Network Defense (CND).
  • Active TS/SCI security clearance.
  • Active IAT Level III certification (e.g., CISSP).
  • 6+ years of experience with Splunk, including Add-ons, Apps, TAs, and Universal Forwarder.
  • Expert knowledge of Splunk, including Splunk Enterprise, Splunk Enterprise Security, and Splunk SOAR.

Responsibilities

  • Design, deploy, and maintain EAC backend architecture.
  • Administer the SOAR platform, including configuration, asset integrations, and custom fields.
  • Design, develop, test, and maintain automated SOAR playbooks for alert triage, enrichment, and risk based response.
  • Integrate SOAR with Splunk Enterprise Security, ticketing systems, and threat intelligence feeds.
  • Manage clustering, replication, indexing performance, and license usage.
  • Apply DISA STIGs, SRGs, and NAVINTEL Information Assurance baselines.
  • Maintain version control, approval workflows, and playbook governance.
  • Configure and maintain the secure transmission of Audit.XML records to Intelligence Community partners through ITS and troubleshoot transmission failures.
  • Implement standard incident response workflows aligned with MITRE ATT&CK, NIST SP 800-61, and HGCC N62 Defensive Cyber Operations procedures.
  • Travel may be required between NMIC and other CONUS/OCONUS locations.

Skills

Splunk Enterprise
Splunk Enterprise Security
Splunk SOAR
Security Clearance TS/SCI
IAT Level III (CISSP)
Threat detection & incident response
SDLC
Verbal & written communication

Education

Bachelor's degree in Computer Science / IT / Information Assurance
Master's degree in related field

Tools

Splunk Add-ons
Splunk Apps
Splunk Technology Add-ons (TAs)
Splunk Universal Forwarder

Job description

Leidos is seeking a Splunk SOAR Administrator in Suitland, MD to provide engineering, operations, and technical support for SIEM platforms supporting threat detection and incident management for the HGCC program.

You will design, deploy, and maintain SOAR playbooks, integrate with Splunk ES and ticketing systems, and ensure secure transmission of Audit.XML records. Active TS/SCI and CISSP-type certification are required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk SOAR Administrator TS/SCI
Senior Splunk SOAR Administrator TS/SCI

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Senior Splunk SOAR Administrator - TS/SCI, SIEM Expert
Senior Splunk SOAR Administrator - TS/SCI, SIEM Expert

G2IT, LLC. • Suitland (MD)

On-site
USD 130,000 - 190,000
Splunk SOAR Administrator
Splunk SOAR Administrator

G2IT, LLC. • Suitland (MD)

On-site
USD 130,000 - 190,000
Splunk SOAR Administrator New Suitland, Maryland, United States
Splunk SOAR Administrator New Suitland, Maryland, United States

G2it, Llc. • Suitland (MD), Northern (KY)

Hybrid
USD 120,000 - 150,000
Senior Splunk SOAR Administrator - SIEM & Threat Response
Senior Splunk SOAR Administrator - SIEM & Threat Response

G2it, Llc. • Suitland (MD), Northern (KY)

Hybrid
USD 120,000 - 150,000
Splunk Enterprise & Enterprise Security Admin (TS/SCI)
Splunk Enterprise & Enterprise Security Admin (TS/SCI)

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
TS/SCI Splunk Administrator – Security Analytics Expert
TS/SCI Splunk Administrator – Security Analytics Expert

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Lead Splunk ES Admin | TS/SCI | SOC Ops - Suitland
Lead Splunk ES Admin | TS/SCI | SOC Ops - Suitland

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
TS/SCI Splunk Administrator - Defensive Cyber Operations
TS/SCI Splunk Administrator - Defensive Cyber Operations

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk SOAR Administrator
Splunk SOAR Administrator

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000