Piper Companies

SIEM/Splunk Engineer - TS/SCI Cleared - 174468 - 174468

Piper Companies$165K — $198K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
  • 5-10+ years of hands-on experience with Splunk Enterprise and Splunk ES
  • Strong expertise in Splunk architecture, SPL development, dashboards, and search optimization
  • Experience with Splunk SOAR (Phantom) and security automation workflows
  • Knowledge of SIEM operations, SOC processes, and incident response
  • Proficiency with Linux/Unix administration and scripting (Python, Bash, PowerShell)
  • Active TS/SCI Security Clearance

Responsibilities

  • Architect and optimize Splunk Enterprise and Splunk ES environments
  • Design scalable and highly available Splunk infrastructures
  • Configure and manage data onboarding and integrations
  • Develop and tune correlation searches and data models
  • Implement and maintain SOAR playbooks and automated workflows
  • Perform health checks, performance tuning, and capacity planning
  • Establish and maintain Splunk governance and compliance standards

Benefits

  • Comprehensive medical, dental, and vision coverage
  • Paid time off and sick leave as required by law
  • Flexible working schedule
  • Unlimited opportunities for professional growth
Full Job Description
Zachary Piper Solutions is seeking an Senior SIEM/Splunk to join a Federal Program located in Newington, VA, onsite 5 days per week. The SIEM/Splunk Engineer will serve as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response.

Responsibilities of the SIEM/Splunk Engineer:
  • Architect, deploy, administer, and optimize Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk SOAR environments.
  • Design and maintain scalable, highly available Splunk infrastructures, including clustering, distributed search, and large-scale data ingestion.
  • Configure and manage data onboarding, parsing, normalization, CIM compliance, and integrations across security, infrastructure, cloud, and application data sources.
  • Develop and tune correlation searches, risk-based alerting (RBA), dashboards, data models, and MITRE ATT&CK-aligned detection content.
  • Implement and maintain SOAR playbooks, automated response workflows, and integrations with security tools, cloud platforms, and ticketing systems.
  • Perform health checks, performance tuning, capacity planning, upgrades, migrations, and platform modernization initiatives.
  • Establish and maintain Splunk governance, RBAC, security hardening, compliance requirements, and operational standards.
  • Automate deployments, configuration management, and administrative tasks using Ansible, Git, Python, Bash, and PowerShell.
  • Collaborate with SOC and Incident Response teams to improve detection capabilities, investigation workflows, and overall security operations.
  • Maintain architecture documentation, operational procedures, playbooks, and technical standards.

Qualifications of the SIEM/Splunk Engineer:
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience)
  • 5-10+ years of hands-on experience with Splunk Enterprise and Splunk ES
  • Experience designing, deploying, and supporting enterprise-scale Splunk environments with clustering, high availability, and large-volume data ingestion.
  • Strong expertise in Splunk architecture, SPL development, dashboards, data models, CIM mapping, and search optimization.
  • Experience with Splunk SOAR (Phantom), security automation, and orchestration workflows.
  • Knowledge of SIEM operations, SOC processes, threat detection, incident response, and MITRE ATT&CK.
  • Experience integrating security technologies including EDR/XDR, IDS/IPS, firewalls, cloud platforms (AWS/Azure/GCP), IAM, and threat intelligence feeds.
  • Proficiency with Linux/Unix administration, networking fundamentals, scripting (Python, Bash, PowerShell), and automation tools such as Git and Ansible.
  • Experience with security hardening, RBAC, SAML, TLS/SSL certificates, and enterprise security compliance requirements.
  • Splunk certifications (Architect, Enterprise Admin, ES Admin, SOAR, or equivalent) strongly preferred.
  • Active TS/SCI Security Clearance

Compensation for the SIEM/Splunk Engineer:
  • Salary Range: $165,000+ *flexible based on experience*
  • Comprehensive Benefits: Medical, Dental, Vision, PTO, and Sick Leave as required by law
  • Flexible working schedule
  • Unlimited opportunities for growth


#LI-CJ2

#LI-ONSITE

Key Words: SIEM, splunk, bash, python, powershell, aws, azure, gcp, mitre, soar, phantom, tcp, udp, upgrades, migrations, edr, fw, ids, ips, cloud logs, cim, mapping, iam, ssl, splunk enterpise, splunk es, spl, configure, manage, engineer, federal, cleared, army, navy, air force, defense, clearance, government, models, dashboards, data models, soc, sme, playbooks, architecture, scripts, scripting, incident response

About Piper Companies

Piper Companies is a staffing and recruiting firm based in Conshohocken, Pennsylvania. It provides staffing solutions for a variety of industries, including technology, healthcare, and finance. The company was founded in 2011 and has since grown to become a leading provider of staffing services in the Philadelphia area. Piper Companies is committed to providing high-quality service to its clients and candidates, and has a strong focus on building long-term relationships. The company is also known for its corporate social responsibility initiatives, including support for local charities and community organizations.
Learn more about Piper Companies
Size
500 employees
Industry

Similar Jobs

More Jobs at Piper Companies

More Information Technology Jobs

Find similar SIEM/Splunk Engineer - TS/SCI Cleared - 174468 - 174468 jobs: