1

Splunk Security Analyst Jobs (NOW HIRING)

Splunk, Sentinel, Vulnerability management tools, ServiceNow * Support automation of compliance and ... Mentor junior analysts and support team development * Promote a culture of security-first ...

KEY TECHNOLOGIES: - SIEM (Splunk, Azure Sentinel, LogRhythm..) - Cisco Security Suite (Secure Malware Analytics, Secure Cloud Analytics, Umbrella) - Cloud (AWS, Azure, GCP) - Linux Systems (Debian ...

They are seeking a Security Analyst who will monitor alerts, investigate incidents, and contribute ... Splunk, CrowdStrike, Sumo Logic, QRadar, Elastic, or similar) • Industry certification: CompTIA ...

... in Splunk Analytics Solid understanding of Cisco ASA Experience in identifying network security vulnerabilities Willingness to respond swiftly and effectively to network security events Must work ...

Security Analyst MUST HAVE: * Experience with implementing a vulnerability scanner * Familiarity ... Experience with a log management system (Splunk, Elastic Search, etc) * General understanding of ...

Security Analyst/Engineer REDMOND, WA- HYBRID NOTES: YOU WILL NEED TO MAKE SURE AND INCLUDE A ... Splunk ES, Crowdstrike, Proofpoint, Wiz to shave on training time • Escalate AD findings • ...

Use scripting and automation to improve SIEM operations and support security analytics. * Support ... Experience supporting Splunk across Windows, Linux, Solaris, and macOS environments. * Hands-on ...

next page

Showing results 1-20

Splunk Security Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do splunk security analyst jobs pay per year?

As of Jun 12, 2026, the average yearly pay for splunk security analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Splunk Security Analyst, and why are they important?

To thrive as a Splunk Security Analyst, you need expertise in cybersecurity principles, strong analytical abilities, and experience with security incident detection and response, often supported by a degree in computer science or related certifications like Splunk Core Certified User or Security+. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is typically required. Strong problem-solving skills, attention to detail, and effective communication set top performers apart in this role. These skills enable analysts to efficiently detect, investigate, and mitigate security threats, ensuring robust protection of organizational assets.

What is a Splunk Security Analyst?

A Splunk Security Analyst is a cybersecurity professional who specializes in using Splunk, a leading Security Information and Event Management (SIEM) platform, to monitor, analyze, and respond to security events within an organization. They are responsible for configuring Splunk dashboards, creating alerts, investigating potential threats, and helping to ensure compliance with security policies. Their work is essential for detecting and mitigating cyber threats, as well as supporting incident response efforts. Splunk Security Analysts often collaborate with IT and security teams to improve the overall security posture of their organization.

What are some typical challenges Splunk Security Analysts face when managing large-scale security events?

Splunk Security Analysts often encounter challenges such as handling high volumes of security alerts and ensuring timely incident response. Effectively parsing and correlating diverse data sources can be complex, especially in organizations with vast or fragmented IT environments. Analysts must prioritize alerts, filter out false positives, and maintain up-to-date detection rules to stay ahead of evolving threats. Collaborating closely with IT, network, and application teams is key to resolving incidents efficiently and improving overall security posture.

What is the difference between Splunk Security Analyst vs SOC Analyst?

AspectSplunk Security AnalystSOC Analyst
CertificationsSplunk certifications, Security+Security+ or GIAC certifications, Splunk certifications
Work EnvironmentSecurity teams, SIEM-focused rolesSecurity Operations Centers, incident response teams
Industry UsageIT security, cybersecurity firms, enterprise securitySecurity operations, threat monitoring, incident handling

Both roles involve security monitoring and require knowledge of SIEM tools like Splunk. A Splunk Security Analyst specializes in using Splunk for security data analysis, while a SOC Analyst performs broader security operations, including incident response and threat detection, often using Splunk as a tool. The roles are complementary, with overlapping skills but different focus areas within cybersecurity teams.

More about Splunk Security Analyst jobs
Infographic showing various Splunk Security Analyst job openings in the United States as of June 2026, with employment types broken down into 4% Full Time, 85% Part Time, and 11% Contract. Highlights an 83% Physical, 8% Hybrid, and 9% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.
Security Analyst

Security Analyst

Core One

Mclean, VA • On-site

Other

Posted 16 days ago


Job description

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

Clearance Required: Active TS/SCI with Polygraph

Summary

We are seeking a Security Analyst to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems. This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions.

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in classified or high-security environments.

Key Responsibilities

  • Lead and support FedRAMP Moderate/High and IC ATO authorization processes
  • Develop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)
  • Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503
  • Perform risk assessments, control assessments, and gap analyses
  • Implement and manage RMF lifecycle activities (Categorize Monitor)
  • Track and manage POA&M remediation activities
  • Facilitate security control inheritance and shared responsibility models
  • Execute continuous monitoring strategies and reporting
  • Analyze security posture using Vulnerability scans and Configuration compliance
  • Produce monthly/quarterly ConMon deliverables
  • Monitor and analyze security events and alerts
  • Support incident response and forensic analysis
  • Coordinate with SOC teams and stakeholders for threat mitigation
  • Conduct root cause analysis and lessons learned
  • Secure cloud environments aligned with FedRAMP controls
  • Implement identity and access controls
  • Support 3PAO assessments and audits
  • Prepare evidence artifacts for FedRAMP JAB/Agency ATO reviews and Inspector General (IG) audits
  • Coordinate with internal/external auditors
  • Utilize security tools for monitoring and compliance: Splunk, Sentinel, Vulnerability management tools, ServiceNow
  • Support automation of compliance and reporting workflows
  • Act as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teams
  • Provide security guidance during system design and change management
  • Mentor junior analysts and support team development
  • Promote a culture of security-first engineering and compliance excellence
  • Contribute to security governance and policy development

Qualifications 

  • Active TS/SCI with Polygraph
  • Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
  • OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
  • Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • At least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
  • Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer

Desired Qualifications

  • Experience with cloud-native security tools
  • Knowledge of Zero Trust Architecture
  • Experience with cross-domain solutions
  • Experience with ICD 503
  • Familiarity with DevSecOps pipelines in regulated environments

Core One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

__PRESENT

__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT


Core One logo

About Core One

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

51 - 200 Employees

Headquarters location

Sterling, VA, US