1

Splunk Sme Jobs (NOW HIRING)

Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector ... Splunk Enterprise Security to detect, analyze, and respond to potential threats or anomalous ...

Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector ... Splunk Enterprise Security to detect, analyze, and respond to potential threats or anomalous ...

The ServiceNow SME will provide expert-level technical leadership throughout the planning ... Integrate ServiceNow with third-party solutions (e.g., Tanium, Splunk), configure connectors ...

Job Title SME- Data Scientist Location Augusta, GA 30905 US (Primary) Category Intelligence Job ... Experience working with IT, business, or operational metrics platforms (e.g., Splunk, Elastic ...

SME Systems Architect

Herndon, VA · On-site

$249K/yr

We are seeking a highly accomplished Subject Matter Expert (SME) Systems Engineer to serve as a ... Splunk, ServiceNow, and AppDynamics to drive end-to-end visibility and operational excellence.

SME Systems Architect

Herndon, VA · On-site

$249K/yr

We are seeking a highly accomplished Subject Matter Expert (SME) Systems Engineer to serve as a ... Splunk, ServiceNow, and AppDynamics to drive end-to-end visibility and operational excellence.

next page

Showing results 1-20

Splunk Sme information

See salary details

$29K

$117K

$158.5K

How much do splunk sme jobs pay per year?

As of Jun 20, 2026, the average yearly pay for splunk sme in the United States is $117,001.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,000.00 and $133,500.00 per year, depending on experience, location, and employer.

What are some common challenges Splunk SMEs face when implementing log management solutions across large organizations?

Splunk SMEs often encounter challenges such as integrating data from diverse sources, ensuring data normalization, and maintaining performance as log volume increases. Coordinating with multiple teams to establish consistent data standards, handling sensitive data securely, and optimizing search queries for efficiency are also common hurdles. Effective communication and collaboration with IT, security, and application teams are essential to address these challenges and deliver scalable, reliable Splunk solutions.

What is the difference between Splunk Sme vs Splunk Administrator?

AspectSplunk SmeSplunk Administrator
CredentialsSplunk certifications, technical expertiseSplunk certifications, system administration skills
Work EnvironmentSecurity, IT operations, data analysis teamsIT operations, system management teams
Employer & IndustryTech, finance, healthcare, security sectorsIT departments across various industries
Search & Comparison IntentUnderstanding role scope, responsibilities, and skillsClarifying job functions, requirements, and career path

The Splunk Sme focuses on providing expert support, troubleshooting, and strategic guidance for Splunk deployments, often working closely with security and data teams. The Splunk Administrator manages daily system operations, configurations, and maintenance of Splunk environments. While both roles require Splunk certifications, the Sme emphasizes expertise and consulting, whereas the Administrator concentrates on system management and stability.

What is a Splunk SME?

A Splunk SME (Subject Matter Expert) is a professional with deep expertise in using and managing Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated big data. Splunk SMEs design and implement Splunk solutions, create dashboards and reports, and help organizations gain insights from their data. They also provide guidance on best practices, perform troubleshooting, and often train other users on how to use Splunk effectively. Their role is essential for organizations looking to leverage Splunk for IT operations, security, and business intelligence.

What are the key skills and qualifications needed to thrive as a Splunk SME, and why are they important?

To thrive as a Splunk SME, you need deep expertise in Splunk architecture, log analysis, and security information and event management (SIEM), typically supported by a degree in IT or related fields and relevant Splunk certifications. Proficiency with Splunk Enterprise, Splunk Apps, scripting languages (like Python or Shell), and experience integrating Splunk with other security tools is essential. Strong analytical thinking, problem-solving abilities, and clear communication skills help in translating technical findings into actionable insights for diverse stakeholders. These skills and qualities are crucial for ensuring robust system monitoring, incident detection, and effective data-driven decision-making within an organization.
More about Splunk Sme jobs
What job categories do people searching Splunk Sme jobs look for? The top searched job categories for Splunk Sme jobs are:
Continuous Monitoring Team Lead (Splunk)

Continuous Monitoring Team Lead (Splunk)

SAIC

Arlington, VA • On-site, Remote

Other

Posted 9 days ago


SAIC rating

7.8

Company rating: 7.8 out of 10

Based on 78 frontline employees who took The Breakroom Quiz

70th of 204 rated it services


Job description

Job ID: 2613574
Location: Arlington, VA, US
Date Posted: 2026-06-10
Category: Cyber
Subcategory: Cyber GRC
Schedule: Full-Time
Shift: Day Job
Travel: Yes - 10% of the time
Minimum Clearance Required: TS.SCI
Clearance Level Must Be Able to Obtain: None
Potential for Remote Work: ORA_ON_SITE
Description
SAIC is seeking qualified applicants to support a cutting-edge data, analytics, and AI platform. The Continuous Monitoring Team Lead (Splunk) is a critical SME role working across Splunk, ServiceNow, and supporting security platform technologies to build analytic maturity and integrations with SOAR, UEBA, and Zero Trust Architecture. Mature analytics and normalized data will support 10+ cyber teams who are also working with other task areas that handle customer relationships, service portfolio and catalog management, software engineering & development, data/AI engineering, IT systems operations, and use case intake and analytics for DoW enterprise-scale mission objectives expected in Spring/Summer 2026.
Positions are contingent pending contract award.
The work will be performed in the Alexandria, Virginia. Some work may be performed remotely, subject to Government approval.
Job Responsibilities:
  • Lead the Continuous Monitoring Team in designing, building, and maturing enterprise cybersecurity analytics across Splunk, supporting continuous monitoring objectives across all CSP/security enclaves.
  • Architect and develop advanced Splunk use cases, dashboards, and custom applications to enable proactive detection, visibility, and decision support for 10+ cyber teams.
  • Design and implement data normalization strategies, including field extractions, CIM alignment, and data model optimization to improve analytic fidelity and reuse.
  • Integrate Splunk with ServiceNow, SOAR platforms, UEBA capabilities, and Zero Trust Architecture to enable automated workflows and enriched operational context.
  • Identify and close visibility gaps by engineering new analytics, correlations, and data onboarding strategies to enhance enterprise monitoring coverage.
  • Collaborate with data/AI engineering teams to incorporate AI/ML-driven analytics, automation, and intelligent alerting into Splunk-based monitoring solutions.
  • Evaluate and optimize data quality, ingestion pipelines, and telemetry sources to ensure high-confidence analytics and reduced false positives.
  • Develop reusable analytic content and patterns based on threat intelligence, lessons learned, and evolving mission requirements, enabling other teams to scale detection and monitoring capabilities.

Qualifications
  • Bachelors & 14+ years of related experience, Masters & 12+ years of experience, or PhD or JD & 9+ years of experience.
  • Active TS/SCI Clearance.

Knowledge, Skills, Abilities, and Competencies:
  • Deep expertise in Splunk architecture, including experience manipulating the functionality of Splunk roles and clustering architectures. Splunk Enterprise Security certification preferred. Splunk Architect, Consultant, or Defense Engineer certification preferred. Splunk Admins with well-defined Splunk App Building experience will be considered. At least a Splunk Administrator certification is required, with growth expectation of achieving Splunk Architect in 12 months or less.
  • Demonstrated ability to build and deploy custom Splunk apps, preferably including development with AI agents in controlled environments and promotion to production.
  • Strong proficiency in data normalization, including field extraction, CIM compliance, and extensive use of Splunk data models for scalable analytics.
  • Advanced understanding of how data quality impacts analytics, CMDB alignment, AI/ML effectiveness, incident noise reduction, and Zero Trust implementations.
  • Experience integrating Splunk with enterprise platforms such as ServiceNow, Splunk SOAR, and Splunk UEBA, and ServiceNow to support automation and operational workflows.
  • Ability to design and deliver analytic outputs and reporting that provide actionable insights into system performance, vulnerabilities, and cybersecurity posture.
  • Relevant DoD 8140 (or 8570 equivalent) certification required; advanced certifications (e.g., CISSP, CCSP) and exposure to AI/ML or data engineering concepts preferred.

SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC's approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see .

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom