1

Splunk Security Analyst Jobs (NOW HIRING)

Join Leidos as a Splunk Security Engineer in Suitland, MD and be at the forefront of mission ... Analyze log events, correlate data across multiple sources, and enhance threat detection and ...

We are seeking a Senior Splunk Security Engineer with 7+ years of experience supporting enterprise ... Monitor security events, analyze logs, investigate incidents, and support SOC operations and ...

Splunk Security Engineer

Suitland, MD · On-site

$107K - $195K/yr

Join Leidos as a Splunk Security Engineer in Suitland, MD and be at the forefront of mission ... Analyze log events, correlate data across multiple sources, and enhance threat detection and ...

They are seeking a Security Analyst to support cybersecurity operations, compliance, and risk ... Splunk, Sentinel, Vulnerability management tools, ServiceNow • Support automation of compliance ...

They are seeking a Security Analyst to support cybersecurity operations, compliance, and risk ... Splunk, Sentinel, Vulnerability management tools, ServiceNow • Support automation of compliance ...

Splunk, Sentinel, Vulnerability management tools, ServiceNow * Support automation of compliance and ... Mentor junior analysts and support team development * Promote a culture of security-first ...

Splunk, Sentinel, Vulnerability management tools, ServiceNow * Support automation of compliance and ... Mentor junior analysts and support team development * Promote a culture of security-first ...

next page

Showing results 1-20

Splunk Security Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do splunk security analyst jobs pay per year?

As of Jul 27, 2026, the average yearly pay for splunk security analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role can be entry-level, but many positions require some prior knowledge of cybersecurity, networking, or security tools like SIEM platforms such as Splunk. Entry-level SOC roles often focus on monitoring and alerting, while more advanced positions may require certifications like CompTIA Security+ or CISSP and experience with incident response. The level of difficulty depends on the specific organization and job requirements.

What are the key skills and qualifications needed to thrive as a Splunk Security Analyst, and why are they important?

To thrive as a Splunk Security Analyst, you need expertise in cybersecurity principles, strong analytical abilities, and experience with security incident detection and response, often supported by a degree in computer science or related certifications like Splunk Core Certified User or Security+. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is typically required. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills enable analysts to efficiently detect, investigate, and mitigate security threats, ensuring robust protection of organizational assets.

Is IT hard to get hired at Splunk?

Getting hired as a Splunk Security Analyst can be competitive, as it requires relevant skills in cybersecurity, data analysis, and experience with Splunk tools. Strong technical knowledge, certifications like Splunk Certified Security Intelligence Expert, and a solid understanding of security principles can improve your chances of securing the role.

How much do Splunk analysts make?

Splunk Security Analysts typically earn between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level roles may start around $60,000, while experienced analysts with advanced skills and certifications can earn over $130,000.

What is a Splunk Security Analyst?

A Splunk Security Analyst is a cybersecurity professional who specializes in using Splunk, a leading Security Information and Event Management (SIEM) platform, to monitor, analyze, and respond to security events within an organization. They are responsible for configuring Splunk dashboards, creating alerts, investigating potential threats, and helping to ensure compliance with security policies. Their work is essential for detecting and mitigating cyber threats, as well as supporting incident response efforts. Splunk Security Analysts often collaborate with IT and security teams to improve the overall security posture of their organization.

What are some typical challenges Splunk Security Analysts face when managing large-scale security events?

Splunk Security Analysts often encounter challenges such as handling high volumes of security alerts and ensuring timely incident response. Effectively parsing and correlating diverse data sources can be complex, especially in organizations with vast or fragmented IT environments. Analysts must prioritize alerts, filter out false positives, and maintain up-to-date detection rules to stay ahead of evolving threats. Collaborating closely with IT, network, and application teams is key to resolving incidents efficiently and improving overall security posture.

What is the difference between Splunk Security Analyst vs SOC Analyst?

AspectSplunk Security AnalystSOC Analyst
CertificationsSplunk certifications, Security+Security+ or GIAC certifications, Splunk certifications
Work EnvironmentSecurity teams, SIEM-focused rolesSecurity Operations Centers, incident response teams
Industry UsageIT security, cybersecurity firms, enterprise securitySecurity operations, threat monitoring, incident handling

Both roles involve security monitoring and require knowledge of SIEM tools like Splunk. A Splunk Security Analyst specializes in using Splunk for security data analysis, while a SOC Analyst performs broader security operations, including incident response and threat detection, often using Splunk as a tool. The roles are complementary, with overlapping skills but different focus areas within cybersecurity teams.

Can you make $500,000 a year in cyber security?

A Splunk Security Analyst typically earns between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires advanced roles such as security manager, director, or executive, along with extensive experience, specialized skills, and often leadership responsibilities. High salaries in cybersecurity are more common in senior or executive positions rather than entry- or mid-level analyst roles.
More about Splunk Security Analyst jobs
What job categories do people searching Splunk Security Analyst jobs look for? The top searched job categories for Splunk Security Analyst jobs are:
Infographic showing various Splunk Security Analyst job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.
Splunk Engineer

Splunk Engineer

Fuse Engineering LLC

Fort George G Meade, MD • On-site

Other

Posted 24 days ago


Job description

Description

The Splunk Engineer is responsible for the design, implementation, optimization, and sustainment of enterprise logging, monitoring, and security analytics solutions. This role ensures Splunk environments meet availability, performance, compliance, and audit requirements .


Key Responsibilities

  • Architect, deploy, and maintain enterprise Splunk environments, including indexers, search heads, forwarders, and multi-region architectures.
     
  • Design, develop, and sustain custom Splunk dashboards and analytics supporting:
     
    • Security events, audit data, and user activity monitoring (UAM)
       
    • STE/STN compliance, vulnerability and compliance scans
       
    • Network/system observable events by SSP
       
    • Containerized application events by namespace
       
    • Mission metrics, outage tracking, and system/network utilization
       
  • Ensure Splunk dashboards and logging infrastructure maintain =93% operational availability monthly.
     
  • Develop and maintain dashboards for authentication events, privileged access, account management, role escalation, and container security events.
     
  • Integrate data from NetFlow/sFlow, Syslog, Cribl, Nagios, HP NNMi, HPNA, vulnerability scanners, and compliance tools.
     
  • Perform Splunk scaling, performance tuning, data onboarding, and index management.
     
  • Maintain log retention policies ensuring:
     
    • 30 days online searchable logs
       
    • 5 years, 11 months offline retention with restore capability
       
  • Provide Tier-4 support, including vendor escalation and coordination with Splunk engineering.
     
  • Advise architects and security accreditors on Splunk security configurations and audit capabilities.
     
  • Develop automation, parsing, and enrichment logic to reduce false positives and enhance alert fidelity.

Requirements

TS/SCI w/ Polygraph Clearance Required


Required Skills

  • Splunk Enterprise architecture and administration
     
  • Security logging, SIEM design, and compliance reporting
     
  • Linux systems administration
     
  • Data onboarding (Syslog, NetFlow, API ingestion)
     
  • Scripting (Python, Bash, SPL)