1

Splunk Siem Engineer Jobs in Silver Spring, MD (NOW HIRING)

This position will provide hands-on administration of the organization's existing Splunk ... on SIEM administration experience and is ready to grow into a broader engineering role. The ...

Administer and monitor core security tools (Splunk SIEM, Tenable, Trellix, Teramind), ensuring ... Hands-on engineering experience administering and maintaining security operations using Splunk ...

The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Understanding of security information and event management (SIEM) concepts. * Proficiency with REST ...

Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases. * Configure, manage ...

The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics across ... SIEM/SOAR integration. Company : Peraton Fearlessly solving the toughest national security ...

The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics ... SIEM/SOAR integration. Company : Peraton Fearlessly solving the toughest national security ...

Splunk Engineer

Herndon, VA · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Riverdale, MD · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Washington, DC · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Herndon, VA · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Herndon, VA · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Herndon, VA · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Splunk Engineer

Riverdale, MD · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Firewall Engineer

Linthicum, MD · On-site

$47.25 - $63.25/hr

Firewall Engineer Location: Linthicum, MD Hybrid The interview is in-person, so kindly share ... Monitor firewall activity logs and integrate log forwarding with Splunk SIEM for real-time threat ...

Splunk Engineer

Washington, DC · On-site

$112K - $179K/yr

Responsibilities The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and ... Experience with automation, orchestration, or SIEM/SOAR integration. Peraton offers enhanced ...

Showing results 41-60

Splunk Siem Engineer information

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

What are popular job titles related to Splunk Siem Engineer jobs in Silver Spring, MD?

For Splunk Siem Engineer jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Splunk Siem Engineer jobs in Silver Spring, MD look for?

The top searched job categories for Splunk Siem Engineer jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Splunk Siem Engineer jobs?

Cities near Silver Spring, MD with the most Splunk Siem Engineer job openings:

Infographic showing various Splunk Siem Engineer job openings in Silver Spring, MD as of August 2026, with employment types broken down into 85% Full Time, 9% Part Time, and 6% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

SIEM Administrator/Engineer

Saic

Washington, DC • On-site

$80 - $120/hr

Other

Posted 12 days ago


SAIC rating

7.6

Company rating: 7.6 out of 10

Based on 81 frontline employees who took The Breakroom Quiz

103rd of 226 rated it services


Job description

Description

SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency's security monitoring and analytics capabilities. This position will provide hands-on administration of the organization's existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security.

The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment.

***This hybrid role requires a minimum of three on-site days per week in Washington, DC.***

Responsibilities
  • Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security.
  • Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases.
  • Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs.
  • Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS).
  • Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search.
  • Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable.
  • Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting.
  • Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity.
  • Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities.
  • Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions.
  • Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes.
  • Maintain technical documentation and take ownership of assigned technical issues and projects through resolution.
Qualifications Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree)
  • 5+ years experience relevant IT/cybersecurity experience.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments.
  • Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting.
  • Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search.
  • Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting.
  • Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise.
  • Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality.
  • Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, HTTP/HTTPS, TLS, and syslog.
  • Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms.
  • Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions.
  • Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages.
  • Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams.
Preferred Qualifications
  • Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash.
  • Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages.
  • Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration.
  • Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments.
  • Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK.
  • Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies.
  • Experience working in or closely supporting a Security Operations Center (SOC).
  • Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications.

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

#J-18808-Ljbffr

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom