2

Remote Splunk Admin Jobs in Washington (NOW HIRING)

... primarily remote with periodic onsite support required in Chantilly, VA and Bluemont, VA. The ... Integrate ServiceNow with third-party solutions (e.g., Tanium, Splunk), configure connectors ...

... primarily remote with periodic onsite support required in Chantilly, VA and Bluemont, VA. The ... Integrate ServiceNow with third-party solutions (e.g., Tanium, Splunk), configure connectors ...

API Developer Lead

Washington, DC · Remote

$135K - $160K/yr

API Developer Lead - Fully Remote (Temp‑to‑Hire) Salary: $135,000-$160,000 The VA Lighthouse ... Administer and optimize Kong Gateway (routes, services, plugins, certificates, rate limiting ...

Cloud Infrastructure Engineer

Mclean, VA · Remote

$56.25 - $75.25/hr

Administer and maintain Linux-based systems (RHEL or similar) * Support patching, updates, and ... Experience with tools such as Splunk, Nessus, or similar * Exposure to identity systems (Active ...

Cloud Infrastructure Engineer

Mclean, VA · On-site +1

$128K - $145K/yr

Administer and maintain Linux-based systems (RHEL or similar) * Support patching, updates, and ... Experience with tools such as Splunk, Nessus, or similar * Exposure to identity systems (Active ...

ServiceNow Developer

Bethesda, MD · On-site +1

$90K - $140K/yr

... remote work within the US. Requirements: Responsibilities * Develop, configure, and customize the ... Required: * ServiceNow Certified System Administrator (CSA) * ServiceNow Certified Application ...

Remote Splunk Admin information

What is the difference between Remote Splunk Admin vs Remote Security Analyst?

AspectRemote Splunk AdminRemote Security Analyst
Required CredentialsSplunk certifications, IT experienceSecurity certifications (CISSP, Security+), IT background
Work EnvironmentIT operations, data management teamsCybersecurity teams, incident response
Industry UsageIT, telecommunications, financeFinance, healthcare, government
Common Search/ComparisonMonitoring Splunk dashboardsAnalyzing security threats

Remote Splunk Admins focus on managing and maintaining Splunk environments, ensuring data is properly indexed and dashboards are operational. Remote Security Analysts concentrate on identifying and mitigating security threats, often using tools like Splunk for threat detection. While both roles require IT knowledge, Splunk Admins specialize in data management, whereas Security Analysts focus on cybersecurity. Both roles are vital in tech-driven industries and often collaborate within IT and security teams.

What is a Remote Splunk Admin?

A Remote Splunk Admin is an IT professional who manages and maintains Splunk environments from a remote location. Their responsibilities typically include installing, configuring, and upgrading Splunk software, managing user access, monitoring system performance, and ensuring data security. They also develop and troubleshoot Splunk queries, dashboards, and alerts to help organizations gain insights from machine-generated data. This role is crucial for organizations leveraging Splunk for security, monitoring, and operational intelligence, and it allows for flexible work arrangements since tasks can be performed offsite.

What are some common challenges faced by remote Splunk Admins, and how can they be addressed?

Remote Splunk Admins often encounter challenges related to managing and securing distributed data sources, maintaining system performance, and ensuring effective communication with cross-functional teams. To address these challenges, it is important to implement robust monitoring practices, automate routine tasks where possible, and use secure remote access protocols. Regularly scheduled virtual meetings and clear documentation can also help foster collaboration with security, IT, and development teams, ensuring smooth operations and quick issue resolution.

What are the key skills and qualifications needed to thrive as a Remote Splunk Admin, and why are they important?

To thrive as a Remote Splunk Admin, you need expertise in Splunk deployment, configuration, and troubleshooting, often supported by a degree in IT or computer science and Splunk certifications like Splunk Certified Admin or Architect. Familiarity with scripting languages, system administration tools, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, effective communication, and the ability to work independently are vital soft skills for this role. These skills ensure reliable system performance, effective data analysis, and seamless support of organizational security and operational objectives.
What are the most commonly searched types of Splunk Admin jobs in Washington? The most popular types of Splunk Admin jobs in Washington are:
What are popular job titles related to Remote Splunk Admin jobs in Washington? For Remote Splunk Admin jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Remote Splunk Admin jobs in Washington look for? The top searched job categories for Remote Splunk Admin jobs in Washington are:
What cities in Washington are hiring for Remote Splunk Admin jobs? Cities in Washington with the most Remote Splunk Admin job openings:
Security Tools Engineer with Security Clearance

Security Tools Engineer with Security Clearance

PKH Enterprises

Washington, DC • Remote

Other

Posted 3 days ago


Job description

Security Tools Engineers – Senior and Junior roles available
Location: National Capitol Region (Remote work but must live in the Washington, DC area for occasional meetings)
Job Type: Full-Time
About the Role:
We are seeking a highly skilled Security Tools Engineers to join our dynamic security operations team. The ideal candidate will have deep expertise in Azure security, endpoint detection, vulnerability management, and security architecture, with hands-on experience in integrating advanced security tools and automating processes. You will be responsible for securing and architecting cloud infrastructure, managing endpoint detection systems, implementing security policies, and leading new software evaluations across a complex enterprise environment.
Key Responsibilities:
1. Azure Security & Cloud Engineering:
o Design, implement, and enforce security policies for Azure subscriptions, including Defender for Cloud, identity baselines, RBAC, and logging.
o Enforce configuration standards across Azure resources at scale using Azure Policy, Blueprints, and landing zones.
o Integrate Azure Activity Logs and Defender alerts into SIEM solutions such as Splunk, ensuring comprehensive monitoring and incident response.
o Secure Azure VMs (Linux and Windows) from baseline to monitoring.
2. Endpoint Detection & Response (EDR) Management:
o Lead the deployment, monitoring, and troubleshooting of EDR solutions (CrowdStrike, SentinelOne) across the enterprise.
o Evaluate and compare CrowdStrike and SentinelOne, and recommend the best solution based on specific use cases.
o Ensure proper EDR agent deployment, validate reporting, and correlate asset data using tools like Axonius, Splunk, and Tenable.
o Troubleshoot and resolve issues where EDR agents fail to report or check in.
3. Carbon Black App Control (Bit9) Management:
o Implement and manage high-enforcement whitelisting policies using Carbon Black App Control.
o Safely onboard new applications and handle block events, determining whether to allow or deny them.
o Manage developer code signing and App Control approvals in a high-enforcement environment.
4. Splunk Configuration and Engineering:
o Configure and troubleshoot Splunk Heavy Forwarders (HF) and Deployment Servers (DS) for efficient data ingestion.
o Manage large-scale Splunk app deployments and validate log source parsing before sending data to production.
o Design and implement custom inputs and ensure optimal performance in data collection and forwarding.
5. Vulnerability Management (Tenable.io):
o Implement and manage Tenable.io vulnerability scanning solutions across a large-scale cloud environment.
o Build and assign scan templates, prioritize vulnerabilities based on risk factors (CVSS, VPR, asset criticality), and ensure remediation.
o Address issues with credential errors in vulnerability scans and improve overall vulnerability management processes.
6. New Software Evaluation & Architecture Support:
o Lead the security review process for new applications and tools, ensuring they meet security gates for permissions, data flow, logging, and compatibility with existing security tools.
o Evaluate vendor tools that require local admin privileges or service account access and ensure proper security assessments are conducted.
7. Linux Support & Hardening:
o Apply Linux hardening controls (e.g., STIG/CIS) to new VMs and automate compliance checks using tools such as Ansible, Lynis, and OpenSCAP.
o Troubleshoot and resolve performance issues on Linux systems, using appropriate diagnostic tools.
8. Scripting & Automation:
o Automate security tasks using PowerShell and Python to streamline processes, such as parsing logs, interacting with APIs (Tenable, CrowdStrike), and managing system configurations.
o Develop scripts to automate security tasks, such as vulnerability scanning, log parsing, and compliance checking.
9. Cross-Team Communication & Collaboration:
o Work closely with other teams to push back on security risks and advocate for necessary security controls in project timelines.
o Document engineering processes and security architectures for repeatability and auditability.
10. Continuous Improvement:
o Lead efforts to continuously improve security posture through research, process refinement, and tool upgrades.
o Identify blind spots or weaknesses in security and proactively implement changes to mitigate risks.
Key Skills & Qualifications:
• Experience:
o 7+ years in Cloud Security Engineering or related roles, with a focus on Azure Security.
o Hands-on experience with security solutions like CrowdStrike, SentinelOne, Carbon Black App Control, and Tenable.io.
o Expertise in Splunk (Heavy Forwarders, Deployment Server) and SIEM architecture.
o Experience with vulnerability management, including scanning, remediation, and prioritization in cloud environments.
• Technical Skills:
o Proficiency with Azure Governance, Azure Policy, and Defender for Cloud.
o Strong scripting skills in PowerShell and Python for automation.
o Experience with Linux system hardening (STIG, CIS), and automation using Ansible or similar tools.
o Solid understanding of security protocols, threat detection, and incident response.
o Proficiency with the following, Suricata/Zeek, Zero Trust (Cloudflare), Cisco Secure Malware Analytics, Whitelisting App notification analysis, • Soft Skills:
o Excellent communication skills, with the ability to articulate complex security issues to non-technical teams.
o Proven ability to work cross-functionally with teams to influence decision-making and enforce security policies.
o Ability to troubleshoot complex security and infrastructure issues