Splunk Administrator / SIEM Analyst
SFI - Crystal City
Description

  

We are seeking a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log ingestion, analytics, and incident response activities within a DISA-domain environment. The selected candidate will operate and administer Splunk and related SIEM/analytics platforms, support server and platform log onboarding, and help prepare analytics capabilities for OCI environments.


This role requires hands-on experience with SIEM administration, security analytics, incident response support, and scripting/automation across tools such as Splunk, Elastic, and other analytics platforms. Experience with WAF, identity systems such as OHS/OAM, and WebLogic is highly desired. PeopleSoft experience is not required, but candidates should understand logging, monitoring, and analytics relevant to enterprise application environments.


Location

Crystal City, VA - On-Site/Hybrid


Work Schedule

Must be available to support either:

  • Day Shift: 0800–1600
  • Swing Shift: 1600–0000


Key Responsibilities

  • Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
  • Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms.
  • Ensure reliable onboarding, normalization, and availability of security and operational logs.
  • Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
  • Support incident response (IR) activities through log analysis, event correlation, and investigative data support.
  • Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
  • Support analytics and logging requirements associated with OCI readiness/preparation.
  • Work within a DISA-domain environment and coordinate with stakeholders across security, infrastructure, and application teams.
  • Support monitoring and analysis for technologies including WAF, identity/access management, OHS/OAM, and WebLogic.
  • Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting.
  • Validate that server, application, and platform data sources are properly integrated into SIEM tools.
  • Document configurations, data flows, standard procedures, and operational issues.
Requirements
  • Must be a U.S. Citizen with an active Secret Clearance
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent operational experience)
  • 5+ years of dedicated engineering experience focused on log management and SIEM platforms. 
  • Certifications: Active CompTIA Security+ (IAT Level II compliant). 
  • Experience administering Splunk in an enterprise environment.
  • Experience with SIEM operations, monitoring, and analytics.
  • Working knowledge of incident response processes and security event investigation.
  • Ability to support log ingestion, parsing, normalization, and platform/server onboarding.
  • Experience scripting or automating tasks within SIEM or analytics platforms.
  • Hands-on experience with one or more of the following: Splunk, Elastic, other SIEM/analytics platforms.
  • Ability to work Day or Swing shift: 0800–1600 or 1600–0000.
  • Experience operating in a DISA-domain or similarly controlled enterprise environment.
  • Strong troubleshooting, analytical, and documentation skills.


Desired Qualifications

  • Experience with Web Application Firewalls (WAF).
  • Experience with identity and access management systems, including OHS/OAM.
  • Experience supporting or monitoring WebLogic environments.
  • Familiarity with OCI logging, monitoring, or analytics preparation.
  • Understanding of logging and analytics for enterprise application platforms.
  • Experience with PeopleSoft is a plus, but not required.


Preferred Skills

  • SIEM content development, correlation rule tuning, and dashboard creation.
  • Scripting with tools/languages used for automation and data handling in SIEM environments.
  • Cross-team coordination with security, system administration, and application support teams.
  • Ability to quickly identify gaps in log coverage and recommend remediation.



Additional Information:

  • All candidates will be subject to a complete background check to include, but not limited to Criminal History, Education Verification, Professional Certification Verification, Verification of Previous Employment and Credit History.
  • Public Trust background investigations can take approximately four to eight weeks and requires fingerprinting.

Other Information:

  • For information on SFI's benefits please visit http://www.spatialfront.com/pages/career.html
  • This is a full-time W2 position. 
  • Please no agencies, third parties, or corp-to-corp.
  • Spatial Front Inc. is an Equal-opportunity Employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
  • Spatial Front Inc. participates in E-Verify.
Salary Description
$100,000-$150,000