Leidos logo
LeidosPosted 3 weeks ago

SRE Cyber Tools - Splunk Admin.

$107,900–$195,050 year

On-siteNorfolk, Virginia, United States

Full TimeEnterprise

Job Summary

Administer, maintain, and perform daily Operations and Maintenance for distributed Splunk Enterprise environments across hybrid cloud and on-premises infrastructure. Monitor platform health, data ingestion, indexing throughput, and search performance while troubleshooting onboarding, parsing, and forwarding issues. Support incident response, outage troubleshooting, root cause analysis, and security compliance activities including STIG remediation and system hardening. Maintain operational documentation, architecture diagrams, and runbooks while participating in after-hours support and an on-call rotation. Work in tandem with development teams to create automated testing frameworks that validate system resilience under normal and stress conditions.

Required Qualifications

  • BS degree and 5-10 years of prior relevant experience or Master's with 4-8 years of prior relevant experience
  • U.S. Citizen and possess an active Secret Security Clearance
  • Minimum of DoD 8570.01 IAT Level II Certification required
  • Vendor certification e.g., Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, Scaled Agile Framework (SaFe)
  • Minimum three years of experience administering Splunk Enterprise v9 and supporting distributed Splunk architectures in hybrid cloud and on-premises production environments
  • Strong working knowledge of Splunk data ingestion pipelines, indexing, parsing, forwarding, search optimization, and retention management
  • Experience administering and troubleshooting Red Hat Enterprise Linux (RHEL) 8 and/or RHEL 9 servers
  • Working knowledge of TCP/UDP networking, SSL certificates, Syslog, REST APIs, and authentication integrations
  • Experience using at least one scripting or automation language: Python, Bash, or PowerShell
  • Ability to work onsite at Norfolk Naval Station Monday through Friday day shift
  • Experience designing, developing, and maintaining operational dashboards, visualizations, and executive reporting in Splunk Enterprise and Splunk Cloud, including IT Service Intelligence (ITSI), Service Analyzer, Glass Tables, and KPI-driven service health monitoring
  • Experience with automated script design, coding, debugging, and maintenance skills (using bash, python, etc.)
  • Strong communication, analytical, and problem-solving skills, ability to work in a team environment
  • Strong troubleshooting, analytical, communication, and documentation skills, with the ability to work independently, manage competing priorities, collaborate across technical teams, and maintain a customer-focused approach in a high-tempo production environment

Desired Qualifications

  • Splunk Core Certified Power User and/or Splunk Enterprise Certified Admin certification
  • Experience supporting Splunk Cloud environments or integrations and both Splunk Enterprise v9 and v10
  • Experience working in classified government or Department of Defense environments
  • Familiarity with STIGs, the Risk Management Framework (RMF), vulnerability management, and compliance frameworks
  • Familiarity with RHEL 10, DevOps practices, and Infrastructure-as-Code concepts
  • Experience with automation or configuration-management tools such as Ansible, Jenkins, Chef, or Terraform

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce