Sr. Splunk Engineer
TS/SCI with FS Poly
Location: Ft. Meade, MD (On-Site)
Job Type: Direct-Hire Full-time
Job Overview:
A Senior Engineer operates independently, ensuring successful project delivery aligned with predefined goals. In this role, a Level I/III Engineer specializes in a key technology area, executes tasks outlined in a statement of work, and communicates any unexpected complexities to senior leadership. As the most senior engineer on a project, they assist Associate and Level I/II Engineers and are expected to be excellent communicators, as they will regularly interact with clients.
How You'll Make an Impact:
- Maintain a master's understanding of the core technologies in your area of responsibility.
- Have an advanced understanding of surrounding technologies in the environment.
- Lead a team of engineers to develop workflows for solving complex issues efficiently.
- Mentor Associate, Level I, and Level II Engineers as needed.
- Spend 5% of time focused on corporate strategy, brand identity, and operations.
- Spend 5% of time on training and skill development.
- Spend 10% of time managing day-to-day operations and career development of team members.
- Spend 80% of time on engagement delivery.
Engagement Management:
- Serve as a mentor for junior engineers.
- Report team issues and provide positive feedback to senior leadership.
- Execute tasks outlined in the scope of work independently.
- Provide assistance for investigation and risk analysis.
- Assist with tier I and II incident response in the security operations center.
- Contribute to tuning performance, reducing low-value searches, and editing searches for performance improvement.
- Assist in configuring correlation searches, dashboard searches, risk modifiers, threat intelligence feeds, workflow actions, and content.
- Automate issue resolution and compliance reporting to improve detection and mitigation times.
- Integrate relevant security products into existing workflows.
Client Engagement:
- Develop and maintain strong client relationships to ensure satisfaction.
- Adhere to availability standards for client inquiries.
- Communicate technical concepts clearly to clients.
- Identify opportunities for cross-sell and up-sell across services.
What We're Looking For:
- Active TS/SCI clearance with FS Poly required.
- Splunk Core Consultant Certification required.
- Splunk Enterprise Security accreditation required.
- Experience with, or interest in, learning and deploying Splunk SOAR.
- Security Certification (e.g., Security+, CISSP, etc.) required.
- Experience operating in classified environments.
- Bachelor's degree or at least 8 years of related experience.
- Strong understanding of identity management, SIEM, cybersecurity, and infrastructure concepts.
- Strong Linux and scripting (Python, Ansible, Terraform, JSON, etc.) experience.
- Ability to troubleshoot Splunk instances and create custom reports, dashboards, and content.
- Solid understanding of governance and compliance, specifically with FAR, DFARs, CUI, and CMMC.
- Familiarity with FedRAMP and IL constructs.
- Strong leadership skills and ability to manage and mentor engineering teams.
- Ability to clearly communicate complex messages to various audiences.
- Excellent problem-solving skills and attention to detail.
- Willingness to travel to meet client needs.