
Cybersecurity Specialist Splunk Engineer
Remote · USJob$100–140K/yrSeen todaySeen in employer's feed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New remote roles like this one, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
SAIC seeks a Cybersecurity Specialist, Splunk Engineer to support the Enterprise Security Operations Center. The role involves administering Splunk and other SIEM tools, developing detections, building dashboards, and integrating security solutions across Azure and AWS environments while collaborating with analysts and stakeholders.
Skills & qualifications
Skills
Qualifications
Full job description
Description
SAIC has an opening for a Cybersecurity Specialist, Splunk Engineer . For the right candidate, this position may be remote anywhere in the United States.
This position is responsible for duties around supporting the tools and technologies that are owned and operated by the Enterprise Security Operations Center. The Splunk Engineer will support other organizations within the company delivering solutions for data-driven challenges that enable the company.
The individual should be knowledgeable on a number of security technologies, have a solid understanding of information security and networking and experience interacting with customers. Will be able to engage on tasks independently, document and communicate work efforts and provide technical support.
The position will be responsible for maintaining and tuning the signatures, interfaces, and technical processes to ensure the tools are operational and meet the requirements of Enterprise Security Operations.
Job Duties:
-
Administer, install, configure, and maintain Splunk (cloud and on prem) and other SIEM/log management tools.
-
Develop, audit, and optimize correlation rules; collaborate with ESOC to create new detections.
-
Build and maintain dashboards, reports, alerts, and visualizations.
-
Create and optimize SPL queries; manage knowledge objects (field extractions, tags, lookups, macros).
-
Onboard and manage data sources (syslog, HEC, forwarders, APIs).
-
Manage deployment servers and forwarders.
-
Maintain inputs, reporting, and alerting across Azure and AWS environments.
-
Work at the system level to improve performance and propose platform enhancements.
-
Develop scripts and integrations with security tools (Python, Bash, PowerShell).
-
Work with workflow automation tools to orchestrate processes with ServiceNow and other security/infrastructure platforms.
-
Use regular expressions (regex) for parsing, extraction, and automation.
-
Document procedures for data ingestion and maintain access controls for compliance.
-
Create and implement configuration standards, policies, and procedures for improved operations.
-
Develop program metrics to measure monitoring effectiveness.
-
Resolve incidents and issues; integrate changes with established change management processes.
-
Train and mentor ESOC members on SIEM capabilities and best practices.
-
Interface with analysts and business stakeholders to ensure tools, dashboards, and applications meet requirements.
-
Communicate effectively with teams and clients.
-
Work across Linux and Windows platforms.
-
Apply an understanding of networking technologies, workflows, and IT reporting
Qualifications
Required Education and Experience:
-
Bachelor’s Degree and 5+ years cybersecurity operation related experience or software analyst/programming related experience, or master’s degree and 3+ years related experience. An additional 4 years of experience may be considered in lieu of a degree.
-
Demonstrated experience administering and engineering Splunk.
-
Must obtain the Splunk Core Certified Admin certification within the first 3 months of employment.
-
Must obtain the Azure AZ-900: Microsoft Azure Fundamentals certification within 6 months of employment.
-
Must obtain the AWS Cloud Practitioner certification within 9 months of employment.
-
Availability to work flexible hours and be available for on call during rotations.
-
Must be a US Citizen.
Target salary range: $100,001 - $140,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
REQNUMBER: 2617557
SAIC is a premier technology integrator, solving our nation's most complex modernization and systems engineering challenges across the defense, space, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We are a team of 23,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $6.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see Working at SAIC. EOE AA M/F/Vet/Disability
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Partner Leader, Solutions Engineer, SplunkCisco · Remote · US · $239–315K/yrPosted 1w agoPosted 1w ago
Customer Success Area TAM Splunk SpecialistCisco · Remote · US · $140–191K/yrPosted 3w agoPosted 3w ago
Account Executive - Splunk Commercial (Remote, CST)Cisco · Remote · US · $139–189K/yrPosted 2w agoPosted 2w ago
Customer Success Splunk Platform Area TAMCisco · Remote · US · $165–209K/yrPosted 2w agoPosted 2w ago
Customer Experience Manager - Splunk (remote)Cisco · Remote · US · $165–209K/yrPosted 5 days agoPosted 5 days ago
You've read the whole posting — now see how you match it.