1

Splunk Uba Jobs (NOW HIRING)

Senior Cybersecurity Architect

Lorton, VA · On-site

$131K - $237K/yr

Hands-on experience with configuring cybersecurity tools and software for enterprise use, with a specific focus on Splunk (Enterprise Security, SOAR, UBA), HBSS/ESS (Trellix ePO), ACAS (Tenable ...

Security Operations Lead

Foster City, CA · On-site

$295K - $385K/yr

Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). * Deep ... Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems.

Showing results 41-45

Splunk Uba information

See salary details

$40

$60

$76

How much do splunk uba jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for splunk uba in the United States is $60.17, according to ZipRecruiter salary data. Most workers in this role earn between $53.12 and $66.35 per hour, depending on experience, location, and employer.

What is Splunk Uba?

Splunk User Behavior Analytics (UBA) is a security solution that uses advanced machine learning to detect insider threats, cyberattacks, and risky behaviors within an organization. It analyzes large volumes of data from various sources to identify abnormal activities and potential threats that traditional security tools might miss. Splunk UBA helps security teams respond more effectively to incidents by providing detailed insights and automated alerts about suspicious user and entity behaviors.

What skills and qualifications are needed to thrive as a Splunk Uba engineer?

To excel as a Splunk UBA Engineer, you need strong expertise in cybersecurity, data analytics, and experience with Splunk platforms, often supported by a degree in computer science or information security. Proficiency in Splunk User Behavior Analytics (UBA), SIEM tools, scripting languages (like Python), and relevant certifications such as Splunk Certified User or Power User is highly valued. Analytical thinking, problem-solving, and effective communication are vital soft skills for interpreting data patterns and collaborating with cross-functional teams. These competencies enable the early detection of insider threats, improve security posture, and ensure seamless integration of UBA solutions within an organization's cybersecurity framework.

What are the typical challenges faced when implementing and maintaining Splunk Uba in an enterprise environment?

Implementing Splunk UBA often involves challenges such as integrating with diverse data sources, ensuring data quality, and tuning detection models to reduce false positives. Team members may need to work closely with IT security, operations, and compliance teams to gather the necessary logs and ensure seamless data flow. Ongoing maintenance includes regular updates, monitoring system performance, and adapting to new security threats, making collaboration and continuous learning essential for success in this role.

What is the difference between Splunk Uba vs Splunk Security Analyst?

AspectSplunk UbaSplunk Security Analyst
CredentialsSplunk certifications, security knowledgeSecurity certifications (e.g., CISSP, CompTIA Security+), SIEM experience
Work EnvironmentSecurity operations centers, IT security teamsSecurity teams, incident response units
Industry UsageCybersecurity, threat detection, complianceSecurity monitoring, incident investigation

Splunk Uba focuses on identifying and prioritizing security threats using machine learning and user behavior analytics, while Splunk Security Analysts interpret security data, investigate incidents, and respond to threats. Both roles require security knowledge and Splunk expertise but differ in their primary functions within cybersecurity operations.

What other helpful pages are available for Splunk Uba?

Other pages related to Splunk Uba:

Infographic showing various Splunk Uba job openings in the United States as of September 2026, with employment types broken down into 91% Full Time, 1% Part Time, and 8% Contract. Highlights an 78% Physical, 9% Hybrid, and 13% Remote job distribution, with an average salary of $125,160 per year, or $60.2 per hour.

Cybersecurity Operations Specialist -SIEM Services (Evergreen)

Saint Louis, MO • On-site

GDIT
IT Services • 10K+ employees

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 13 days ago


Key responsibilities

  • Perform cybersecurity data analysis and manage SIEM capabilities, including design, development, configuration, and operation.

  • Maintain system availability and reliability, perform scheduled and emergency maintenance, and troubleshoot SIEM data flows and event parsing.

  • Configure, integrate, and test assets and data flows to ensure proper ingestion, transmission, and interoperability with reporting systems.


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz


Job description

Type of Requisition:

Pipeline

Clearance Level Must Currently Possess:

Top Secret/SCI

Clearance Level Must Be Able to Obtain:

Top Secret SCI + Polygraph

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Analytics, ArcSight SIEM, ElasticSearch, Kibana

Certifications:

None

Experience:

6 + years of related experience

US Citizenship Required:

Yes

Job Description:

GDIT is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in At Louis, MO.

The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.

Job Duties Include:

  • Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
  • Maintain system availability and reliability with a threshold of 99.99%
  • Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
  • Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
  • Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
  • Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
  • Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
  • Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
  • Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NCE laws, directives, orders, polices, guidance, procedures etc.
  • Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN - Joint Incident Management System, DoD CIO - DoD Scorecard/Get to Green reporting, IC CIO - Cybersecurity Performance Evaluation Model reporting, etc.)
  • Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
  • Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services

Required Skills:

  • SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
  • Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
  • Create SIEM playbooks
  • Linux (RHEL) Expert (administration and engineering)
  • Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
  • Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
  • Creation of ArcSight rules based on use cases of malicious events
  • Tuning and aggregation of queries and filters
  • Skilled in troubleshooting event flow through Enterprise Audit infrastructure
  • Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
  • Active TS/SCI Clearance
  • DoW 8570.01-M IAT Level II and CSSP Infrastructure Support certifications
  • 6+ years Experience with SIEM and Development Projects
  • 6+ years Experience with SIEM support for projects and technical exchange meetings
  • 6+ years Experience developing and maintaining enterprise audit projects

Desired Skills:

  • Kibana
  • Data Analytics
The likely salary range for this position is $128,039 - $173,229. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Onsite

Work Location:

USA MO St. Louis

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US