1

Splunk Cybersecurity Defense Analyst Jobs in Washington

ASRC Federal is seeking a highly skilled and experienced Cyber Defense Analyst (Threat Hunter) to ... Maintain and upkeep various cybersecurity applications and tools on servers and workstations to ...

The Senior Cyber Defense Analyst will serve as a senior-level cybersecurity operations professional ... Extensive hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or ...

Cyber Defense Analysts - Senior

Washington, DC · On-site

$113K - $146K/yr

The Senior Cyber Defense Analyst will serve as a senior-level cybersecurity operations professional ... Extensive hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or ...

The Senior Cyber Defense Analyst will serve as a senior-level cybersecurity operations professional ... Extensive hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or ...

Must be able to obtain DHS Suitability * BS Computer Science, Cyber Security, Computer Engineering ... Substantial knowledge of Splunk (or other SIEM's) * Understanding of MITRE Adversary Tactics ...

Showing results 21-40

Splunk Cybersecurity Defense Analyst information

How does a Splunk Cybersecurity Defense Analyst typically collaborate with other IT and security teams?

A Splunk Cybersecurity Defense Analyst frequently works alongside network administrators, incident response teams, and other security professionals to detect, investigate, and remediate threats. Collaboration often involves sharing threat intelligence, creating automated alerts, and developing dashboards to provide visibility into security events across the organization. Analysts also participate in regular meetings to coordinate response strategies, review incident post-mortems, and ensure that Splunk configurations align with evolving security requirements. This cross-functional teamwork is essential for maintaining an effective and proactive cybersecurity posture.

What is a Splunk Cybersecurity Defense Analyst?

Splunk Cybersecurity Defense Analysts are professionals who use the Splunk platform to monitor, analyze, and defend an organization’s digital infrastructure against cyber threats. They collect and interpret security data, investigate incidents, and create alerts and dashboards to detect suspicious activity in real-time. Their work helps organizations respond quickly to threats, ensuring the safety and integrity of sensitive information and systems. These analysts often collaborate with IT and security teams to develop best practices for threat detection and response.

What are the key skills and qualifications needed to thrive as a Splunk Cybersecurity Defense Analyst, and why are they important?

To thrive as a Splunk Cybersecurity Defense Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, typically supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is essential. Strong analytical thinking, problem-solving abilities, and effective communication are important soft skills for collaborating with teams and responding to security incidents. These skills and qualities are critical for quickly identifying, investigating, and mitigating cyber threats to protect organizational assets.

What is the difference between Splunk Cybersecurity Defense Analyst vs Security Operations Center (SOC) Analyst?

AspectSplunk Cybersecurity Defense AnalystSecurity Operations Center (SOC) Analyst
CertificationsSplunk certifications, CompTIA Security+CompTIA Security+, GIAC certifications
Work EnvironmentPrimarily uses Splunk platform for data analysisMonitors security alerts across various tools in a SOC
Industry UsageFinancial, healthcare, tech sectors leveraging SplunkBroadly in all sectors with security teams
Job FocusAnalyzing security data with Splunk, threat detectionMonitoring, incident response, alert management

While both roles focus on cybersecurity, the Splunk Cybersecurity Defense Analyst specializes in using Splunk for data analysis and threat detection, whereas the SOC Analyst performs broader security monitoring and incident response across multiple tools. The roles often overlap but differ in platform focus and scope of responsibilities.

What are popular job titles related to Splunk Cybersecurity Defense Analyst jobs in Washington? For Splunk Cybersecurity Defense Analyst jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Splunk Cybersecurity Defense Analyst jobs in Washington look for? The top searched job categories for Splunk Cybersecurity Defense Analyst jobs in Washington are:
What cities in Washington are hiring for Splunk Cybersecurity Defense Analyst jobs? Cities in Washington with the most Splunk Cybersecurity Defense Analyst job openings:
Infographic showing various Splunk Cybersecurity Defense Analyst job openings in Washington as of August 2026, with employment types broken down into 88% Full Time, 6% Contract, and 6% Nights. Highlights an 100% In-person job distribution.

Cyber Defense Analyst - Overnights

asrcfh

Quantico, VA • On-site

Other

Posted 25 days ago


Job description

ASRC Federal is seeking a highly skilled and experienced Cyber Defense Analyst (Threat Hunter) to join our dynamic team on the Overnight shift (1900 – 0700), providing extended-hours coverage that includes weekend and holiday rotations (Four 10-hour shifts per work week). This is a fully on-site position at Quantico Marine Corps Base, VA — no telework is available for this role.

The successful candidate will perform robust network security monitoring and proactively identify potential threats across our enterprise infrastructure. This role is critical for defending mission systems, conducting in-depth traffic and vulnerability analysis, and maintaining a strong security posture in support of Department of War (DoW) missions.

Position Description: 

The Cyber Defense Analyst (Threat Hunter) is a vital role responsible for performing comprehensive network security monitoring and proactive threat hunting during swing-shift, weekend, and holiday coverage windows. This position focuses on safeguarding the network through continuous traffic analysis, vulnerability and wireless scanning, and leveraging enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).

The Analyst will collaborate with cross-functional IT and security teams to:

  • Implement Information Assurance Vulnerability Management (IAVM) programs
  • Manage Network Access Control
  • Provide insider threat support
  • Monitor data at rest
  • Review web content filtering
  • Maintain and upkeep various cybersecurity applications and tools on servers and workstations to ensure high operational readiness during all covered hours

Minimum Requirements: 

  • At least five (5) Years – Hands-on technical cybersecurity experience and knowledge of Computer Network Defense concepts, DISA Security Technical Information Implementation Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
  • Bachelor’s degree in information technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet 8570 certification requirements at the time of hire. IAT Level II (e.g., CCNA Security, CySA +, GICSP, GSEC, Security+, SSSP or a CSSP Auditor Certification CEH, CISA, GSNA is preferred).
  • Willingness and availability to work the swing shift (1430 – 2300), including weekend and holiday rotations, fully on-site at Quantico, VA.

Required Skills:

  • Log Analysis & Threat Identification: Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to identify possible security threats (e.g., determine rogue systems, infected systems, unauthorized system changes, and unauthorized hardware connections).
  • Policy Enforcement: Ability to identify violations of internet access by reviewing web content filtering logs in accordance with DoD policy, and Standard Operating Procedures (SOPs).
  • Task Management: Experience in processing and handling JFHQ DODIN Cyber related tasks to completion.
  • Proactive Threat Hunting: Performance of threat hunting activities using DoD approved cyber tools through data hunting, manipulation, and presentation, including generating queries and reports for management and the end-customer.
  • Incident Assessment: Validation and confirmation of critical security events and assessing the impact of the event, by incorporating data from multiple tool sources.
  • Investigation & Forensics: Identifying evidence of illegal activity involving cybercrime offenses and examining computers that may have been involved in other types of crime or malware infection.
  • Malware Analysis: Use of forensic tools and investigative methods to find specific electronic data, namely associated with performing complex malware analysis.
  • Process Documentation: Experience developing and maintaining SOPs for security monitoring.
  • Reporting: Provide daily/weekly/monthly reports to senior leadership on key indicators of network security.

Work Environment and Physical Demands: 

  • This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.
  • Must work the assigned Overnight shift (1900 – 0700) and support weekend and holiday coverage as scheduled consisting of Four 10-hour shifts per work week.
  • Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.