Splunk UBA Engineer

Leidos

Suitland (MD)

On-site

USD 108,000 - 195,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos in Suitland, MD is seeking a Splunk UBA Engineer to join our security team. You will provide engineering, operations, and technical support for SIEM platforms that enable threat detection, compliance, and security incident management for the HGCC.

The role includes administering the SOAR and UBA platforms, configuring baselines and risk scoring, monitoring analytics, and supporting RMF/A&A activities, with occasional travel between NMIC and CONUS/OCONUS locations.

Qualifications

  • Active TS/SCI clearance required.
  • IAT Level III certification (e.g., CISSP).
  • 8+ years of engineering experience in Computer Network Defense.
  • 6+ years of experience with Splunk and associated components.
  • Expert knowledge of Splunk components including UBA, ES, and Enterprise.
  • Experience with SDLC and security engineering practices.
  • Strong problem-solving and communication skills.

Responsibilities

  • Administer the SOAR platform configuration and integrations.
  • Administer the UBA platform, including data ingestion and validation.
  • Configure baselines, peer group analysis, modeling, and risk scoring.
  • Monitor UBA pipeline health and analytic coverage.
  • Tune anomaly detection to reduce false positives and improve detection.
  • Validate UBA insights against security incidents and integrate findings into Splunk ES.
  • Support UBA upgrades and analytic refresh cycles.
  • Support RMF and A&A activities.
  • Recommend architectural and security improvements.
  • Travel may be required between NMIC and other CONUS/OCONUS locations.

Skills

Active TS/SCI clearance
Strong analytical skills
Effective communication

Education

Bachelor's degree in Computer Science/Information Technology/Information Assurance
Master's degree (in lieu: 15+ years experience)

Tools

Splunk
Splunk Enterprise
Splunk Enterprise Security
Splunk UBA
Splunk Add-ons / Apps / TA
Universal Forwarder
SOAR

Job description

Description

Leidos is hiring a Splunk UBA Engineer to join our team in Suitland, MD. In this role, you will provide engineering, operations, and technical support for Security Information and Event Management (SIEM) platforms that enable threat detection, compliance, and security incident management for the Office of Naval Intelligence's Hopper Global Communications Center (HGCC). You will help optimize user behavior analytics, strengthen threat detection capabilities, and support mission critical defensive cyber operations.

Primary Responsibilities
  • Administer the SOAR platform, including configuration, asset integrations, and custom fields.
  • Administer the User Behavior Analytics (UBA) platform, including configuration, data source ingestion, and validation.
  • Configure behavioral baselines, peer group analysis, user, device, and entity modeling, and risk scoring thresholds.
  • Monitor UBA pipeline health, model accuracy, and analytic coverage.
  • Tune anomaly detection logic to reduce false positives and improve threat detection accuracy.
  • Validate UBA insights against known security incidents and integrate findings into Splunk Enterprise Security.
  • Support UBA platform upgrades and analytic refresh cycles.
  • Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities.
  • Recommend architectural and security improvements.
  • Travel may be required between the National Maritime Intelligence Center (NMIC) and other designated CONUS and OCONUS locations in support of program requirements.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Information Assurance, or a related discipline with 8+ years of relevant experience, or a Master's degree with 6+ years of relevant experience. 15+ years of experience, including at least 10 years supporting LAN/WAN technologies, may be considered in lieu of a degree.
  • Active TS/SCI security clearance.
  • Active IAT Level III certification (such as CISSP).
  • 8+ years of engineering experience supporting Computer Network Defense (CND).
  • 6+ years of experience with Splunk, including Splunk Add-ons, Apps, Technology Add-ons (TAs), and Universal Forwarder.
  • Expert knowledge of Splunk and its components, including Splunk Enterprise, Splunk Enterprise Security, and Splunk User Behavior Analytics (UBA).
  • Significant experience with the System/Software Development Life Cycle (SDLC).
  • Strong analytical and problem solving skills.
  • Effective verbal and written communication skills.
Pay Range

Pay Range $107,900.00 - $195,050.00

Original Posting

August 4, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date of August 4, 2026.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay And Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk UBA Engineer
Splunk UBA Engineer

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk SOAR Engineer
Splunk SOAR Engineer

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Splunk SOAR Engineer
Splunk SOAR Engineer

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Senior Splunk Engineer
Senior Splunk Engineer

Leidos • Arlington (VA)

On-site
USD 131,000 - 237,000
Splunk SOAR Engineer
Splunk SOAR Engineer

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Senior Splunk Engineer
Senior Splunk Engineer

Leidos Inc • Arlington (VA)

On-site
USD 131,000 - 237,000
SRE Cyber Tools - Splunk Admin.
SRE Cyber Tools - Splunk Admin.

Leidos • Norfolk (VA)

On-site
USD 108,000 - 195,000
SRE Cyber Tools - Splunk Admin.
SRE Cyber Tools - Splunk Admin.

Leidos Inc • Norfolk (VA)

On-site
USD 110,000 - 195,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
SRE Cyber Tools - Splunk Admin.
SRE Cyber Tools - Splunk Admin.

Leidos • United States

On-site
USD 108,000 - 195,000