1

Splunk Security Engineer Jobs (NOW HIRING)

Splunk Enterprise Certified Admin or SumoLogic Administration or Microsoft Security Operations Analyst Associate * AWS Solutions Architect Professional or AWS DevOps Engineer Professional or Azure ...

Senior Splunk Engineer

Portland, OR · On-site +1

$125K - $148K/yr

The Senior Splunk Engineer designs, implements, maintains, and optimizes Splunk capabilities that ... Security Analytics & Detection Support * Develop, maintain, and tune SPL searches, correlation ...

next page

Showing results 1-20

Splunk Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do splunk security engineer jobs pay per year?

As of Jul 23, 2026, the average yearly pay for splunk security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Splunk Security Engineer position, and why are they important?

To thrive as a Splunk Security Engineer, you need strong expertise in cybersecurity principles, log analysis, and experience with Splunk Enterprise or Splunk Cloud platforms, often supported by a related degree or certifications like Splunk Certified Power User or Architect. Familiarity with SIEM tools, scripting languages (e.g., Python), and integration of security data sources is essential. Strong problem-solving, attention to detail, and excellent communication skills help you collaborate effectively with IT and security teams. These skills are crucial for proactively detecting threats, improving system security, and ensuring an organization's digital safety.

What does a typical day look like for a Splunk Security Engineer?

A typical day for a Splunk Security Engineer involves monitoring security alerts and dashboards, investigating and responding to potential threats, and fine-tuning Splunk queries or correlation searches. You may work closely with SOC analysts, network engineers, and system administrators to interpret security logs, uncover patterns, and implement new detection rules or data integrations. Additionally, you might help with onboarding new data sources into Splunk and contribute to incident response activities or post-incident reviews. The role is highly collaborative and often fast-paced, requiring a blend of analytical and technical skills to keep organizational data secure.

What is a Splunk Security Engineer job?

A Splunk Security Engineer is responsible for implementing, managing, and optimizing Splunk for security operations. They design and maintain Splunk infrastructure, create alerts and dashboards, and analyze security logs to detect threats. Their role involves integrating Splunk with various security tools and developing custom use cases for threat detection and response. Additionally, they collaborate with security teams to enhance monitoring capabilities and ensure compliance with organizational security policies.

More about Splunk Security Engineer jobs
What cities are hiring for Splunk Security Engineer jobs? Cities with the most Splunk Security Engineer job openings:
What are the most commonly searched types of Splunk Security Engineer jobs? The most popular types of Splunk Security Engineer jobs are:
What states have the most Splunk Security Engineer jobs? States with the most job openings for Splunk Security Engineer jobs include:
What job categories do people searching Splunk Security Engineer jobs look for? The top searched job categories for Splunk Security Engineer jobs are:
Infographic showing various Splunk Security Engineer job openings in the United States as of July 2026, with employment types broken down into 96% Full Time, 1% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.
Splunk Security Engineer with Security Clearance

Splunk Security Engineer with Security Clearance

Quantum Science Solutions

Reston, VA • On-site

Other

Posted 23 days ago


Job description

Job Title: Splunk Security Engineer Location: Reston, VA Clearance: Active TS/SCI with Polygraph Required Company: Quantum Science Solutions (QSS) Compensation: Open Rate Position Overview Quantum Science Solutions (QSS) supports mission-critical cybersecurity operations for customers within the IC. We are seeking an experienced Splunk Security Engineer to design, implement, and optimize enterprise-scale Splunk environments supporting classified cyber defense operations. The Splunk Security Engineer will serve as a technical leader responsible for engineering and maintaining Splunk Enterprise and Splunk Enterprise Security (ES) environments, integrating enterprise log sources, enhancing threat detection capabilities, and supporting Security Operations Center (SOC) missions. This individual will work closely with cybersecurity engineers, system administrators, cloud engineers, and mission stakeholders to improve security visibility, automate operational processes, and ensure compliance with federal cybersecurity standards across highly secure government environments. Key Responsibilities • Design, deploy, administer, and optimize enterprise-scale distributed Splunk Enterprise and Splunk Enterprise Security (ES) environments. • Integrate enterprise log sources including operating systems, network devices, cloud platforms, applications, databases, and security tools using Universal Forwarders, APIs, and Syslog. • Develop custom dashboards, reports, visualizations, alerts, and correlation searches supporting threat hunting, incident response, governance, and executive reporting. • Configure and maintain Splunk Common Information Model (CIM), field extractions, event types, tags, macros, and knowledge objects to improve data normalization and search accuracy. • Optimize search performance, indexing, storage utilization, and distributed Splunk architecture to improve operational efficiency. • Automate Splunk engineering, deployment, administration, and onboarding activities using Python, Bash, Ansible, reusable scripts, and YAML-based configurations. • Onboard new enterprise data sources while developing standardized ingestion and automation processes. • Support Security Operations Center (SOC) missions through advanced log analytics, SIEM engineering, and detection content development. • Support Incident Response (IR), digital forensics, and cyber threat detection through advanced security monitoring and log analysis. • Assist with implementation of Zero Trust Architecture (ZTA), Continuous Monitoring (ConMon), Risk Management Framework (RMF), and ICD 503 security requirements. • Develop and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), and other Assessment & Authorization (A&A) artifacts. • Provide technical guidance regarding Splunk architecture, SIEM tuning, cyber policy compliance, and Authorization to Operate (ATO) sustainment. • Produce engineering documentation, configuration guides, standard operating procedures, and change management documentation. • Ensure compliance with NIST 800-53, CNSSI 1253, ICD 503, and DoD STIG security requirements. • Collaborate with cross-functional engineering teams to support secure enterprise cybersecurity operations and mission objectives. Mandatory Skills • U.S. Citizenship • Active TS/SCI Clearance with Polygraph • 10+ years of cybersecurity experience supporting secure government or Intelligence Community environments • Minimum 5 years of hands-on Splunk engineering experience supporting classified environments • Extensive experience administering: Splunk Enterprise, Splunk Enterprise Security (ES), Distributed Splunk environments, Splunk clustering, Common Information Model (CIM) • Experience integrating enterprise log sources across infrastructure, cloud, network, application, and security platforms. • Strong experience developing dashboards, searches, alerts, correlation rules, and security visualizations. • Experience optimizing Splunk search performance and indexing architecture. • Proficiency with Linux operating systems and Linux command-line administration. • Experience with Python and Bash scripting. • Experience supporting Incident Response, Threat Hunting, Digital Forensics, or Security Operations Center (SOC) environments. • Knowledge of: NIST 800-53, RMF, ICD 503, Continuous Monitoring (ConMon), Zero Trust Architecture • Experience supporting AWS, GovCloud, C2S, VMware, or other secure cloud environments. • Excellent written and verbal communication skills with the ability to communicate effectively with technical teams and government stakeholders. Preferred Skills • Splunk Certified Power User • Splunk Certified Administrator • Splunk Enterprise Security Certified Administrator • Experience with infrastructure automation using Ansible, Terraform, or Jenkins. • Experience integrating threat intelligence feeds into Splunk. • Experience developing advanced correlation searches and detection content. • Experience supporting DHS, ODNI, or other Intelligence Community organizations. • Experience with DevSecOps practices and Infrastructure as Code (IaC). • Familiarity with multi-tenant enterprise cybersecurity environments. Education Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Information Systems, Engineering, or a related technical discipline. OR High School Diploma with equivalent directly related cybersecurity and Splunk engineering experience. Desired Certifications • CISSP, Security+, AWS Certification Why QSS? At QSS, you'll support mission-critical cybersecurity operations protecting government systems and critical infrastructure from evolving cyber threats while working alongside experienced cybersecurity professionals.