Building. Solving. Serving.
Sr Splunk Engineer
Location
United States
Posted
9 days ago
Salary
$150K - $165K / year
No structured requirement data.
Job Description
Senior Splunk Engineer
This position requires an active Public Trust clearance to be considered.
A government contract requires that this position be restricted to U.S. citizens or legal permanent residents. You must provide documentation that you are a U.S. citizen or legal permanent resident to qualify.
We are seeking a Senior Splunk Engineer to architect, build, and operate Splunk Enterprise and Enterprise Security (ES) across hybrid environments with a strong emphasis on AWS. You will own the Splunk platform end to end—ingest, CIM mapping, ES content, search and dashboard performance, SOAR automations, and ServiceNow IR integrations. You will drive detection, response, and reporting outcomes that meet FISMA/NIST RMF, FedRAMP, and CMMC requirements. You will implement robust governance, RBAC, change control, and audit-ready evidence. You will partner with SOC, IR, cloud, and platform teams to deliver measurable risk reduction and operational efficiency.
Compensation & Benefits:
Estimated starting salary range: $150,000- $165,000. Pay commensurate with experience.
Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits. Benefits may change with or without notice.
Senior Splunk Engineer Responsibilities Include:
Design, deploy, and maintain Splunk Enterprise, indexers, search heads (including SHC), cluster master/CM, deployment server/Deployer, forwarders, and KV stores across on‑prem and AWS.
Engineer scalable data onboarding pipelines, parsing, and indexing with props/transforms, HEC, UF/HF, and S3/SQS/SNS-based ingestion.
Enforce RBAC, data retention, index strategy, knowledge object governance, and change control aligned to federal compliance.
Optimize search performance, data model accelerations, KV store usage, and ES notable event throughput and latency.
Develop and tune ES correlation searches, risk-based alerting (RBA), and adaptive response actions mapped to MITRE ATT&CK.
Build dashboards, investigations, and notable event workflows that reduce false positives and drive analyst efficiency.
Maintain CIM-compliant data models; lead normalization and data quality initiatives across cloud, endpoint, identity, and network sources.
Measure and report detection and response efficacy (MTTR, precision/recall, RBA risk scores, SLA adherence).
Engineer Splunk SOAR (Phantom) playbooks and apps with secure, scalable configurations to triage, enrich, and contain threats.
Integrate ES notables with automated triage and ServiceNow IR for incident creation, enrichment, SLA tracking, approvals, and evidence attachments.
Build AWS-focused detection and response: GuardDuty, CloudTrail, Security Hub, VPC Flow Logs, IAM, EC2, S3; implement safe actions (e.g., EC2 isolation, S3 access updates, EBS snapshots, IAM key rotation/MFA enforcement, Security Hub updates) with human-in-the-loop approvals and rollback.
Integrate EDR and identity platforms for host containment, IOC blocking, and remote response via APIs.
Lead Splunk deployments in AWS including scalability, multi-account/multi-region ingestion, and cross-account automation via Boto3 and native services.
Standardize reusable Python modules, SDK usage, and CI/CD practices for app/deployment packaging and version control.
Map controls to FISMA/NIST RMF, FedRAMP, and CMMC; maintain audit-ready evidence through logging, approval trails, and configuration baselines.
Drive POA&M updates, control validations, and continuous monitoring dashboards.
Champion secrets management, least privilege, and safe-response guardrails in all platform and automation changes.
Translate SOC/IR runbooks (phishing, malware, IAM abuse, EC2 compromise) into reliable detections and automations.
Mentor junior engineers and analysts on SPL, ES content development, CIM, and SOAR playbooks.
Partner with stakeholders to prioritize use cases and deliver quantifiable outcomes.
Other duties as assigned.
Experience, Education, Skills, Abilities
7+ years in security engineering, SOC/IR, or platform engineering, including 4+ years designing and operating Splunk Enterprise and Splunk ES in production.
3+ years hands-on with Splunk SOAR (Phantom) and automation of ES notables and ServiceNow IR workflows.
Strong AWS experience: GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs; cross-account and multi-region preferred.
Proven ServiceNow Incident Response integration experience.
Proficiency in SPL, Python, AWS Boto3, Splunk/Phantom SDKs, REST APIs, and Git-based version control.
Deep knowledge of CIM, data model accelerations, index/retention strategy, and search performance tuning.
Strong grasp of MITRE ATT&CK, CVE/CVSS, CISA KEV, and risk-based detection and automation.
Experience aligning operations with FISMA/NIST RMF, FedRAMP, and CMMC; evidence generation and audit support.
Preferred: Splunk certifications (Core Certified Power User/Admin/Architect, ES Admin), AWS certifications, Security+, CySA+, CISSP, GCDA/GCSA.
Preferred: Experience with Splunk SHC, DS/Deployer, KVstore management, ES content management at scale, AWS Organizations, and ServiceNow IR customization/change management integrations.
Must pass pre-employment qualifications of Cherokee Federal.
Company Information
Criterion is a part of Cherokee Federal – the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.
Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.
#LI-SM2 #Appc
Similar Searchable Job Titles
Senior Splunk Engineer
Splunk ES Engineer
Senior Security Analytics Engineer
Security Automation Engineer
Security Orchestration Engineer
Keywords
Splunk Enterprise
Splunk ES
Splunk SOAR
AWS
Security Analytics
Incident Response,
ServiceNow IR
CIM
RBA
Automation
Legal Disclaimer: All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Executive focusing on cybersecurity solutions in the Dallas Metro area.
Information Security Architect
Stefanini GroupThe Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia. More than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence.
Lead and produce system threat models for integration of commercial components into a Data Lake platform. Review Cloud architectures with security lens. Propose effective security controls within the environment and identify and suggest mitigations for security vulnerabilities. S...
Legal Advisor
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This role offers a unique opportunity to influence and shape the evolving legal function within a fast-paced GovTech SaaS environment. You will work closely with business and technical leaders to navigate a diverse array of legal challenges, from commercial contracting to regulat...
Security Advisor III
ProficioProficio provides 24/7 security monitoring, threat detection, alerting and response services.
SUMMARY:Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufa...