1

Splunk Phantom Jobs (NOW HIRING)

Engineer and manage all SOAR using Splunk Phantom. * Integrate security use cases into Phantom. * Develop reusable, testable, and efficient Python-based Playbooks. * Configure and program to enable ...

Be Seen First

Linux and Windows proficiency is required. • Responsible for ensuring the operational readiness of SOC applications to include but not limited to Splunk Enterprise Security, Splunk Phantom and ...

Be Seen First

Linux and Windows proficiency is required. • Responsible for ensuring the operational readiness of SOC applications to include but not limited to Splunk Enterprise Security, Splunk Phantom and ...

Familiarity with Phantom, Cloud computing, Web Interfaces, Databases, Big Data technologies (like Hadoop, Kafka etc) * Understanding of Continuous Delivery and Continuous Integration * Splunk Admin ...

Familiarity with Phantom, Cloud computing, Web Interfaces, Databases, Big Data technologies (like Hadoop, Kafka etc) * Understanding of Continuous Delivery and Continuous Integration * Splunk Admin ...

Familiarity with Phantom, Cloud computing, Web Interfaces, Databases, Big Data technologies (like Hadoop, Kafka, etc.). Understanding of Continuous Delivery and Continuous Integration. Splunk Admin ...

Design, deploy, document, and maintain distributed Splunk SOAR (Phantom) platform architecture to ensure high availability, scalability, and performance. * Support system upgrades, patching, and ...

SOAR Engineer

Gainesville, VA · On-site

$95K - $105K/yr

Experience with playbook development using Security Orchestration and Automated Response (SOAR) platforms such as Tines, Palo Alto XSOAR, Splunk Phantom, or Swimlane * Experience with programming ...

Google Chronicle, Splunk, Phantom SOAR, CRIBL, , Log stash * Any other SIEM platforms like IBM QRadar etc Education/Experience: * Bachelor's degree in Computer Science OR Information technology and ...

next page

Showing results 1-20

Splunk Phantom information

See salary details

$58

$80

$91

How much do splunk phantom jobs pay per hour?

As of Jul 31, 2026, the average hourly pay for splunk phantom in the United States is $80.95, according to ZipRecruiter salary data. Most workers in this role earn between $74.76 and $88.46 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Splunk Phantom position, and why are they important?

To excel as a Splunk Phantom professional, you should have a solid background in cybersecurity, incident response, and familiarity with security orchestration, automation, and response (SOAR) platforms. Proficiency in using Splunk Phantom (now known as Splunk SOAR), scripting languages like Python, and relevant certifications such as Splunk Certified SOAR Administrator are highly valued. Strong problem-solving, communication skills, and an aptitude for collaborating across security and IT teams help set candidates apart. These abilities enable effective automation of security workflows, optimizing incident response and enhancing organizational defenses.

What is a Splunk Phantom job?

A Splunk Phantom job involves working with Splunk's Security Orchestration, Automation, and Response (SOAR) platform to automate cybersecurity operations. Professionals in this role configure and manage playbooks, integrate security tools, and streamline incident response. Their responsibilities may include threat hunting, data enrichment, and developing automated workflows to enhance security efficiency. This role is ideal for security analysts, engineers, and automation specialists who want to improve response times and reduce manual efforts in cybersecurity operations.

Which Phantom job is best?

In the context of Splunk Phantom, roles such as Security Analyst or Security Engineer are common, focusing on incident response, automation, and security orchestration. The best job depends on your skills in cybersecurity, scripting, and familiarity with security tools, as well as your career goals. Certifications like CISSP or GIAC can enhance prospects in these roles.

What are some common challenges faced by professionals working with Splunk Phantom, and how can they prepare for them?

Professionals working with Splunk Phantom often face challenges around integrating diverse security tools, creating and managing effective playbooks, and keeping up with the fast-paced nature of security threats. It’s important to stay updated on the latest SOAR best practices and maintain a strong understanding of both the platform’s technical capabilities and the broader security environment. Collaboration with other cybersecurity team members and continuous learning allow you to identify gaps, optimize automation, and adapt to evolving threats. By proactively addressing these areas, you’ll be better equipped to maximize the value of Splunk Phantom in your organization.

Is it hard to get hired at Splunk?

Getting hired for a Splunk Phantom role typically requires relevant experience in security automation, scripting, and familiarity with the platform. Strong technical skills, certifications, and a good understanding of cybersecurity concepts can improve chances, but the hiring process is competitive and often involves technical assessments and interviews.

What is phantom in Splunk?

In the context of a Splunk Phantom analyst or security professional, Phantom refers to Splunk Phantom, a security orchestration, automation, and response (SOAR) platform that helps security teams automate incident response workflows. It enables analysts to streamline threat detection, investigation, and remediation processes using playbooks and integrations with various security tools.

What is a phantom job?

A Phantom job in the context of Splunk Phantom refers to an automated or scheduled task that runs within the security orchestration, automation, and response platform. These jobs help security teams automate incident response processes, often involving playbooks and scripts to handle alerts efficiently. Understanding how to manage and troubleshoot Phantom jobs is important for security analysts and automation engineers.
More about Splunk Phantom jobs
Infographic showing various Splunk Phantom job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 90% Full Time, 5% Part Time, and 4% Contract. Highlights an 90% Physical, 4% Hybrid, and 6% Remote job distribution, with an average salary of $168,372 per year, or $80.9 per hour.

Cybersecurity Automation Engineer

General Dynamics Information Technology

Fayetteville, NC • On-site

$127K - $172K/yr

Full-time

Retirement, PTO

Posted 27 days ago


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

85th of 220 rated it services


Job description

Share
REQ#: RQ223578Public Trust: None Requisition Type: Regular Your Impact

Own your opportunity to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure.

Job Description

Advance your career while impacting our national security in cyber as a Senior Principal Cybersecurity Automation Engineer at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

The Senior Principal Cybersecurity Automation Engineer will be responsible for utilizing Splunk Phantom for engineering and managing all Security Orchestration Automation Response (SOAR). This role demands an experienced Security Threat Engineer with a robust technical skill set and direct experience in integration and playbook development for Splunk Phantom. The engineer will support automation for various security functions including incident handling, incident response, intrusion analysis, threat hunting, digital forensic analysis, vulnerability scanning, Data Loss Prevention (DLP), and other cyber and information assurance automation activities.

WHAT YOULL NEED TO SUCCEED

Key Responsibilities

  • Engineer and manage all SOAR using Splunk Phantom.

  • Integrate security use cases into Phantom.

  • Develop reusable, testable, and efficient Python-based Playbooks.

  • Configure and program to enable seamless integration of Phantom with other systems.

  • Extend the platform by developing Security Apps.

  • Train and mentor security development teams on the capabilities of Phantom.

  • Use available tools and the Phantom platform to enable automation and orchestration.

  • Collaborate with the customer to identify security integration and implementation strategies, developing their expertise in Phantom.

  • Define requirements for creative integrations and playbooks.

  • Partner with security operations teams, threat intelligence groups, and incident responders.

  • Codify workflows into automated playbooks.

  • Implement and develop Phantom's flexible app model, using numerous tools and APIs.

  • Utilize Python scripts, PowerShell, and Linux commands for integrations.

  • Drive efficient communication with integrated collaboration tools.

  • Use Phantom event and case management for rapid triage of events.

  • Notify CND managers, incident responders, and team members of suspected CND incidents and provide detailed event histories, statuses, and potential impacts.

  • Coordinate with higher authorities on actual or attempted intrusions, viruses, and other events.

  • Implement and enforce CND policies and procedures adhering to applicable laws and regulations.

  • Provide incident reports, summaries, and situational awareness information to higher headquarters.

  • Manage incidents from inception to after-action reporting.

Required Qualifications

  • 8+ years of relevant experience

  • 8570 Certification: Minimum certification IAT level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+ CE, SSCP); Level III preferred (e.g., CISSP, GCIH, GCFA, GCIA, GNFA, Linux+, CCNA R&S, Splunk Power User)

  • Experience with Splunk Phantom, Linux, and PowerShell

Preferred Qualifications

  • Experience installing and configuring Phantom.

  • Experience in integrating security use cases into Phantom.

  • Expertise in developing Python scripts, PowerShell, and using Linux commands.

Critical Soft Skills

  • Ability to multi-task and adapt to changing priorities in highly stressful situations.

  • Highly resilient and motivated to investigate unfamiliar problems in a high OPTEMPO environment.

  • Critical thinking skills for applying and correlating data from multiple sources to solve complex problems.

  • Strong ability to articulate operational impacts of cybersecurity incidents/events to leadership.

  • Effective communication skills and the ability to build strong relationships with other teams.

Location

  • On Customer Site

Security Clearance

  • TS/SCI Required

Citizenship Required

  • US Citizenship

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.

Growth: AI-powered career tool that identifies career steps and learning opportunities

Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace

#armajobs
Work Requirements
Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification
Travel Required

10-25%

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $127,500 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

Our Identity Verification Process

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans


What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US