Must be a US Citizen; this position requires access to customer data. All internals must have Manager's approval to transfer. Required Qualifications- U.S. citizenship. Work is performed in a federally controlled environment.
- Hands-on production administration of a SIEM or large-scale data platform - Splunk, Elastic, Microsoft Sentinel, Chronicle, QRadar, or comparable - including data onboarding, access administration, and capacity management.
- Demonstrated automation of administrative work: scripting in Python, PowerShell, or Bash, and configuration management such as Ansible, applied to real production tasks. Be prepared to describe specific manual processes you replaced and what that saved.
- Working fluency with platform REST APIs for bulk auditing, configuration, and tooling.
- Git and version-controlled configuration, including experience deploying platform configuration or content through an automated pipeline.
- Strong query skills in at least one platform language (SPL, KQL, Lucene or ES DSL, or SQL), with specific before and after performance results the candidate can describe.
- Linux administration fundamentals: services, filesystems, networking, TLS, and log troubleshooting.
- Excellent written documentation skills. Be prepared to provide a writing sample such as a runbook, design document, or migration plan you authored.
- Demonstrated change management discipline and the ability to own a workstream end to end with little oversight.
Preferred Qualifications- Splunk administration experience, a current Splunk Enterprise or Cloud Certified Admin, or an equivalent certification on another major SIEM. Splunk is the current primary platform.
- Ansible at scale: roles and playbooks for platform configuration, application deployment, and agent or forwarder management across many hosts.
- Infrastructure as code (Terraform or CloudFormation) and hands-on cloud administration, AWS preferred.
- CI/CD pipeline construction (GitLab CI, GitHub Actions, or Jenkins) for configuration and content deployment.
- Containers and orchestration (Docker, Kubernetes).
- Data pipeline and log routing tooling such as Cribl, Kafka, or Kinesis Firehose.
- Experience with a second SIEM or data platform, or with a large-scale platform migration or consolidation.
- Administration of multiple environments or enclaves, including regulated environments such as FedRAMP or IL5.
- Security operations context: detection engineering, log source coverage, SOC support, or premium security content such as Enterprise Security or ITSI.
- Capacity planning and subscription cost control for a metered platform.
Requisition ID: 459616 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
Requisition ID: 459616
Posted Date: Sep 3, 2026
Work Area: Information Technology
Career Status: Professional
Employment Type: Regular Full Time
Expected Travel: 0 - 10%
Location: