SIEM Platform Migration (Splunk to Elastic) * Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack ...
SIEM Platform Migration (Splunk to Elastic) * Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack ...
SIEM Platform Migration (Splunk to Elastic) * Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack ...
SIEM Platform Migration (Splunk to Elastic) * Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack ...
Splunk Engineer
Camp Springs, MD · On-site
Support SIEM data ingestion, indexing, normalization, dashboarding, alerting, and operational reporting. * Develop dashboards and visualizations for security, operations, and mission stakeholders.
Splunk Engineer
Camp Springs, MD · On-site
Support SIEM data ingestion, indexing, normalization, dashboarding, alerting, and operational reporting. * Develop dashboards and visualizations for security, operations, and mission stakeholders.
The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security ...
The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security ...
They are hiring an experienced Cyber Threat Analyst (I&W) with expertise in Splunk SIEM and Analyst1 to monitor and analyze cyber threats targeting the Department of State's information systems.
They are hiring an experienced Cyber Threat Analyst (I&W) with expertise in Splunk SIEM and Analyst1 to monitor and analyze cyber threats targeting the Department of State's information systems.
Support SIEM data ingestion, indexing, normalization, dashboarding, alerting, and operational reporting. * Develop dashboards and visualizations for security, operations, and mission stakeholders.
Support SIEM data ingestion, indexing, normalization, dashboarding, alerting, and operational reporting. * Develop dashboards and visualizations for security, operations, and mission stakeholders.
Splunk Engineer 104-001
Washington, DC · On-site
SOAR, IT Services Infrastructure (ITSI), User Behavior Analysis (UBA), or ES (SIEM). Works with customers to plan and implement complex Splunk customer solutions. Skill Level 4 : * Skills and Tasks
Splunk Engineer 104-001
Washington, DC · On-site
SOAR, IT Services Infrastructure (ITSI), User Behavior Analysis (UBA), or ES (SIEM). Works with customers to plan and implement complex Splunk customer solutions. Skill Level 4 : * Skills and Tasks
Cybersecurity Lead
$117K - $158K/yr
ACAS | HBSS | Splunk | SIEM | eMASS
Cybersecurity Lead
$117K - $158K/yr
ACAS | HBSS | Splunk | SIEM | eMASS
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Cyber Threat Analyst (I&W) with Splunk and Analyst1 / Active Top Secret
Arlington, VA · On-site
$104K - $166K/yr
Responsibilities Peraton is hiring an experienced Cyber Threat Analyst (I&W) with Splunk SIEM and Analyst1 threat intelligence platform experience for our Federal Strategic Cyber Programs. Location:
Splunk Engineer
Reston, VA · On-site
Support, admin, maintain, and expand Splunk infrastructure to meet future architecture design and ... Experience in Security information and event management (SIEM) * Experience with RTIR
Splunk Engineer
Reston, VA · On-site
Support, admin, maintain, and expand Splunk infrastructure to meet future architecture design and ... Experience in Security information and event management (SIEM) * Experience with RTIR
Cybersecurity Lead
Quantico, VA · On-site
$117K - $158K/yr
ACAS | HBSS | Splunk | SIEM | eMASS
Cybersecurity Lead
Quantico, VA · On-site
$117K - $158K/yr
ACAS | HBSS | Splunk | SIEM | eMASS
Splunk Engineer
Reston, VA · On-site
Support, admin, maintain, and expand Splunk infrastructure to meet future architecture design and ... Experience in Security information and event management (SIEM) * Experience with RTIR
Splunk Engineer
Reston, VA · On-site
Support, admin, maintain, and expand Splunk infrastructure to meet future architecture design and ... Experience in Security information and event management (SIEM) * Experience with RTIR
... Splunk SIEM to correlate cybersecurity alerts. * 2+ years of experience using Endpoint Detection and Response (EDR) to conduct incident response. * 3+ years of experience using operating system ...
Quick apply
... Splunk SIEM to correlate cybersecurity alerts. * 2+ years of experience using Endpoint Detection and Response (EDR) to conduct incident response. * 3+ years of experience using operating system ...
... Splunk SIEM to correlate cybersecurity alerts. * 2+ years of experience using Endpoint Detection and Response (EDR) to conduct incident response. * 3+ years of experience using operating system ...
... Splunk SIEM to correlate cybersecurity alerts. * 2+ years of experience using Endpoint Detection and Response (EDR) to conduct incident response. * 3+ years of experience using operating system ...
The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Understanding of security information and event management (SIEM) concepts. * Proficiency with REST ...
The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Understanding of security information and event management (SIEM) concepts. * Proficiency with REST ...
Splunk Engineer
Mclean, VA · On-site
... SIEM principles. Preferred : • Splunk Certification (Admin or Architect) • Experience with Ansible tower automations • Experience using Gitlab • Experience with large platform migration ...
Splunk Engineer
Mclean, VA · On-site
... SIEM principles. Preferred : • Splunk Certification (Admin or Architect) • Experience with Ansible tower automations • Experience using Gitlab • Experience with large platform migration ...
The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Understanding of security information and event management (SIEM) concepts. * Proficiency with REST ...
Quick apply
The Senior Splunk Engineer will be responsible for designing, implementing, and optimizing Splunk ... Understanding of security information and event management (SIEM) concepts. * Proficiency with REST ...
Splunk Engineer
Herndon, VA · On-site
The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics across ... SIEM/SOAR integration. Company : Peraton Fearlessly solving the toughest national security ...
Splunk Engineer
Herndon, VA · On-site
The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics across ... SIEM/SOAR integration. Company : Peraton Fearlessly solving the toughest national security ...
Splunk Siem information
What is the difference between Splunk Siem vs Splunk Security Analyst?
| Aspect | Splunk Siem | Splunk Security Analyst |
|---|---|---|
| Primary Role | Monitoring, analyzing, and managing security data using Splunk SIEM tools | Interpreting security data, investigating threats, and responding to security incidents |
| Required Skills | Splunk SIEM configuration, log analysis, security monitoring | Security incident response, threat detection, Splunk analysis |
| Certifications | Splunk Certified User/Power User, Security certifications | CompTIA Security+, CISSP, Splunk certifications |
| Work Environment | Security operations centers, IT departments | Security teams, incident response units |
Splunk Siem professionals focus on configuring and maintaining Splunk SIEM systems for security monitoring, while Splunk Security Analysts interpret security data, investigate threats, and respond to incidents. Both roles require knowledge of Splunk tools and security principles, but the Security Analyst role emphasizes active threat response and analysis.
What are popular job titles related to Splunk Siem jobs in Washington?
For Splunk Siem jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Splunk Siem jobs in Washington look for?
The top searched job categories for Splunk Siem jobs in Washington are:
Full-time
Posted 4 days ago
Job description
SMX is seeking a Security Information and Event Management (SIEM) Engineer responsible for implementing, configuring, and managing SIEM environments to support the organization's data analytics, security, and operational goals. This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the SIEM infrastructure. The scope of this position includes all Army Intelligence security domains as defined by the Cybersecurity Director, and the Engineer will verify that all solutions and configurations meet the required security standards and compliance requirements. Additionally, the SIEM Engineer is responsible for ensuring ICS 500-27 audit compliance, maintaining the integrity and security of the SIEM system, and collaborating closely with analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.
This is a full-time onsite position in Ft. Meade, MD.
Essential Duties & Responsibilities
SIEM Platform Migration (Splunk to Elastic)
Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack (Elasticsearch, Logstash, Kibana), including planning, stakeholder coordination, execution, and post-migration validation to ensure zero degradation in security monitoring and detection coverage.
Develop and manage the migration roadmap and program schedule, defining phased cutover milestones, resource requirements, and risk mitigation strategies while ensuring parallel operation of both platforms during transition to maintain continuous threat detection and incident response readiness.
- Splunk Implementation and Maintenance:
- Set up and configure Splunk instances, including forwarders, indexers, and search heads.
- Onboard new data sources into Splunk while ensuring proper parsing, field extraction, and indexing.
- Manage Splunk licenses, user access controls, and configurations to maintain stability and security.
- Data Analysis and Visualization:
- Build and optimize dashboards, alerts, and reports for security monitoring, IT operations, and business use cases.
- Develop and enhance Splunk Search Processing Language (SPL) queries to facilitate advanced analytics.
- Collaborate with teams to ensure that data sources meet the requirements for analysis and visualization.
- Troubleshooting and Performance Tuning:
- Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.
- Optimize queries, alerts, and settings to lower resource use and improve efficiency.
- Resolve data ingestion and indexing issues.
- Service Level Agreement (SLA) Management and Monitoring:
- Maintain and monitor the Service Level Agreement (SLA) of the Splunk system, ensuring that the system meets the required uptime, performance, and data ingestion targets.
- Monitor the ingest of data sources, particularly high-value or high-impact systems, and alert stakeholders when these systems stop sending events or experience disruptions.
- Develop and implement monitoring dashboards and alerts to quickly identify and respond to SLA breaches or data ingest issues.
- Disaster Recovery and High Availability:
- Design and implement disaster recovery and high availability solutions for the Splunk system, ensuring minimal downtime and data loss in the event of a disaster or system failure.
- Develop and maintain disaster recovery plans, including backup and restore procedures, to ensure business continuity.
- Configure and manage Splunk clustering, replication, and indexing to ensure high availability and redundancy.
- Compliance and Security:
- Maintain RMF (Risk Management Framework) ATO (Authority to Operate) compliance for the Splunk system, ensuring that all security controls and configurations are in place and up-to-date.
- Ensure STIG (Security Technical Implementation Guide) compliance for the Splunk system, including configuration and vulnerability management.
- Maintain accurate and up-to-date documentation, including:
- Data flow diagrams to illustrate data ingestion and processing.
- Architecture diagrams to depict the Splunk system architecture.
- System inventories to track hardware and software components.
- Collaborate with the security team to ensure that the Splunk system meets all relevant security requirements and standards.
- SIEM Management:
- Manage the onboarding process for new systems and log types, including:
- Maintaining onboarding documents for each system/log type.
- Developing and maintaining a detailed list of event codes per operating system and application type.
- Ensure that all data sources are properly configured and sending events to the Splunk system.
- Collaborate with analysts and architects to develop and implement use cases for security monitoring and incident response.
- Collaboration and Support:
- Collaborate with architects and analysts to create and implement solutions that align with the organization's objectives.
- Provide technical support and assist end users with Splunk-related issues, ensuring timely resolution and minimal downtime.
- Documentation and Continuous Improvement:
- Document the configurations, workflows, and troubleshooting procedures to enhance team knowledge sharing.
- Research and suggest enhancements to Splunk infrastructure and analytics capabilities.
Required Skills, Experience & Education
- Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for SAP and CI Poly).
- Certifications:
- Splunk Enterprise Certified Architect
- Security+ (or above)
- Education
- Bachelor's degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.
- Technical Skills
- 2-3 years of experience an Elastic SIEM environment
- Proficiency in managing Splunk components including forwarders, indexers, and search heads.
- Strong understanding of SPL and the capacity to create custom dashboards and reports.
- Experience in data parsing, field extraction, and indexing.
Desired Skills/Experience
- Experience transitioning a SIEM environment from Splunk to Elastic
- Experience supporting Splunk Enterprise Security (ES) or IT Service Intelligence (ITSI).
- Familiarity with scripting languages (e.g., Python, Bash) for automation.
- Knowledge of security operations, including SIEM best practices.
Application Deadline: September 28, 2026
#CJPOST
#LI-onsite
About SMX
Sourced by ZipRecruiter
Our tradition of delivering innovative, technical solutions dates back to 1995, however, you may know us better by one of our legacy company names: Trident Technologies, Smartronix, Datastrong or C2S Consulting Group. With the support of OceanSound Partners, our private equity investment sponsor, we began operating as one business starting in 2019 and became SMX in 2021. We operate in close proximity to our clients around the globe and have core locations in Alabama, California, DC Metro, Florida, Hawaii, Maryland, and Massachusetts. Today, as SMX, we are one team and together empower government and commercial enterprises to become more effective, innovative, and resilient, no matter what challenges they face.
Industry
It services
Company size
1,001 - 5,000 Employees
Headquarters location
Hollywood, MD, US