Splunk Enterprise and Enterprise Security Administrator

Leidos

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Suitland, MD
Salary
$107,900–$195,050 / yr
Employment
Full-time
Posted
20 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $184k
This role $151k
$94k most similar roles pay here $239k

This role pays less than 78% of similar roles. Most pay $154,450–$214,000 — the shaded band above. At the midpoint, this role pays about $151k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 357 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 305 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Splunk Enterprise and Enterprise Security Administrator

The Splunk Enterprise and Enterprise Security Administrator joins the team to maintain the NAVINTEL SIEM environment while supporting SOC operations. This role involves administering Splunk Enterprise, Enterprise Security, CIM compliance, correlation searches, RBAs, dashboards, and data models. The individual will be responsible for onboarding new data sources, ensuring quality, parsing, and normalization, as well as performing incident response, threat hunting, detection engineering, and content governance. They will produce operational reports, posture summaries, and detection documentation. Key technical requirements include proficiency in Splunk Enterprise/ES, search processing language (SPL), CIM mapping, Linux administration, and the installation of Splunk Add-ons, Apps, TA, and Universal Forwarders. The position focuses on solving security challenges within a Computer Network Defense environment by performing SIEM tuning and managing RMF functions to ensure robust information security for critical infrastructure.

What you'll do

  • Administer Splunk Enterprise and Enterprise Security platforms including CIM compliance and correlation searches.
  • Engineer detection logic and develop custom dashboards for security monitoring.
  • Onboard new data sources while ensuring proper parsing, normalization, and data quality.
  • Support incident response activities and proactive threat hunting operations.
  • Perform detection engineering and manage content governance for the SIEM environment.
  • Produce operational reports, posture summaries, and detailed detection documentation.
  • Tune SIEM workflows to support ongoing Security Operations Center (SOC) requirements.

What we're looking for

  • Bachelor's degree in CS, IT, IA, or a related field with 8+ years of experience.
  • Master's degree with 6+ years of experience.
  • Active TS/SCI security clearance.
  • Demonstrated experience supporting Computer Network Defense (CND) operations and technologies.
  • 6+ years of professional experience in Splunk Enterprise, Add-ons, Apps, TA, and Universal Forwarder installation and administration.
  • Deep experience with Splunk Enterprise/ES, search processing language (SPL), CIM mapping, dashboards, and Linux administration.
  • Experience supporting SOC workflows and SIEM tuning.
  • DoD 8570 CSSP Infrastructure Support certification category (e.g., CEH, CySA+, CASP+, CISSP).

More like this

Similar roles

Splunk Engineer

SpaceX

Redmond, WA 9 days ago $130,000–$165,000
Splunk SPL Python Puppet Ansible Linux Git CI/CD infrastructure-as-code Regex Common Information Model Splunk SOAR Splunk Machine Learning Toolkit EDR Site Reliability Engineering DevOps

Security Operations Center Analyst

Booz Allen Hamilton

Columbia, MD 21 days ago $69,400–$158,000
Splunk SIEM Incident Response Linux CLI Nix Bro Zeek Suricata Snort Nessus Firewall Configuration SOAR Splunk Phantom Threat Intelligence AI
2+ yrs exp

Enterprise Endpoint Security Architect

Salesforce

Remote (Bellevue, WA) 33 days ago $218,400–$365,200
EDR XDR CSPM SSPM AWS Azure Kubernetes Docker Terraform Jenkins Spinnaker GitLab ELK Grafana AppDynamics Scrum DMARC
10+ yrs exp Remote

Senior Enterprise Security Engineer

Upstart

Remote (Burlingame, CA) +3 178 days ago $164,800–$228,400
Data Security Least-Privilege Access DLP Data Classification SOC 1 SOC 2 SOX Information Security
5+ yrs exp Remote

Enterprise Security Architect, Lead

Booz Allen Hamilton

McLean, VA +1 81 days ago $86,800–$198,000
Security Architecture Zero Trust NIST SP 800‑53 F5 Palo Alto DLP Encryption SASE AWS Azure SIEM SOAR DevSecOps Kubernetes RMF FedRAMP ISO 27001
7+ yrs exp