Peraton logo
PeratonPosted 7 months ago

Splunk Engineer

$112,000–$179,000 year

On-siteWashington, District of Columbia, United States or Herndon, Virginia, United States

Full TimeMid LevelBachelors DegreeEnterprise

Job Summary

Design, develop, and maintain custom Splunk dashboards, alerts, and reports to support NOC and SOC operations. Onboard new data sources using forwarders, APIs, and syslog integrations while implementing data normalization via the Splunk Common Information Model. Develop optimized SPL queries, regex extractions, and macros for high-performing searches and visualizations. Configure threshold-based and adaptive alerts for system performance, security, and application availability. Collaborate with analysts to define KPIs and ensure accurate visibility into network health and security posture. Support incident detection, triage, and root cause analysis using Splunk tools. Monitor Splunk Enterprise and Cloud environments, integrate with automation/orchestration platforms like Ansible and SOAR, and document processes per SOPs. Requires TS/SCI clearance and 5+ years of experience. Peraton supports federal/DoD missions with enhanced benefits.

Required Qualifications

  • TS/SCI with polygraph clearance adjudication or ability to obtain SCI and pass a poly
  • Bachelor's degree in an area applicable to the position with 5+ years relevant experience
  • Active CompTIA Security+, CySA+, CASP+, CISSP, or equivalent DoD 8570 IAT Level II
  • 3–5 years of hands-on experience administering, configuring, and developing within Splunk Enterprise or Splunk Cloud environments
  • Demonstrated experience designing and maintaining custom dashboards, reports, and alerting frameworks
  • Strong proficiency in Splunk Search Processing Language (SPL), field extractions, and data model creation
  • Familiarity with Linux and Windows server environments, network protocols (TCP/IP, SNMP, syslog), and application log ingestion
  • Understanding of NOC/SOC workflows, event correlation, and log management best practices
  • Experience troubleshooting data ingestion, indexing, and search performance issues
  • Excellent communication, documentation, and collaboration skills

Desired Qualifications

  • Current Splunk Core Certified Power User, Admin, or Architect certification
  • Experience supporting federal or DoD environments and familiarity with RMF (Risk Management Framework)
  • Experience with Python scripting, REST APIs, or JSON/XML parsing for custom integrations
  • Working knowledge of NIST 800-53/171, and log retention / audit evidence requirements
  • Experience with automation, orchestration, or SIEM/SOAR integration

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce