Sr. Splunk Administrator

Core4ce

$120K — $145K *
US-AnywhereRemote in United States
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Top Secret security clearance required.
  • High school diploma or GED; technical bachelor’s degree preferred.
  • 8+ years of IT experience, including 1+ years with Splunk as administrator or power user.
  • Experience in federal or DoD settings preferred but not mandatory.
  • Industry certification in technologies like Windows OS or AWS preferred.
  • Proficient in scripting languages such as Bash, Python, and PowerShell.
  • Splunk Enterprise Certified Admin certification preferred; must obtain within 6 months if not held.
  • CompTIA Security+ or equivalent certification required within 6 months if not held.

Responsibilities

  • Use Splunk SPL to develop queries, alerts, and dashboards for clients.
  • Assist users in accessing audit logs for troubleshooting and compliance.
  • Configure dashboards for clients to analyze audit logs effectively.
  • Onboard data adhering to quality standards and CIM compliance.
  • Install, configure, and deploy Splunk infrastructure components at scale.
  • Support deployments with data feeds from various global locations.
  • Maintain Splunk performance and recommend enhancements as needed.
  • Act as a liaison for Splunk-related technical inquiries and issues.

Benefits

  • Flexible work responsibilities to encourage individual growth.
  • Opportunities for continued education and certification advancements.
Full Job Description
Job Description

Core4ce is seeking a Senior Splunk Administrator to support mission-critical, classified DoD programs. This role is responsible for the design, deployment, administration, and optimization of enterprise Splunk environments supporting cybersecurity, operational monitoring, and compliance initiatives within secure enclaves.

The ideal candidate will have deep expertise in Splunk Enterprise, Splunk ES, and distributed architectures, with experience operating in classified (TS/SCI) environments and supporting RMF, continuous monitoring, and Zero Trust initiatives.

Responsibilities
  • Demonstrated experience using Splunk Search Processing Language to assist customers in creating queries, setting alerts, identifying event conditions, and building dashboards. Develop reliable, efficient, and re-usable queries that will drive custom alerts and dashboards
  • Assist users in accessing and identifying relevant audit logs, both for troubleshooting and cybersecurity compliance purposes.
  • Assisting customers in configuring dashboards to facilitate their own audit log analysis, and generally assisting customers in developing Splunk solutions for their use cases.
  • Data onboarding to high data quality standards and CIM compliance.
  • Installing, configuring, and deploying Splunk infrastructure, to include search heads, indexers, forwarders, and other Splunk components in large deployment.
  • Support large-scale deployment with data feeds from multiple locations worldwide
  • Monitor and maintain Splunk performance, availability, and capacity. Recommend configuration changes to improve the performance, stability or usability of the platform.
  • Work independently, take initiative, and proactively troubleshoot and resolve platform issues.
  • Act as the Splunk liaison for Splunk technical questions, issues or escalations. This will include working with Splunk Support, Product Management or others as needed.

*This position is designed to be flexible, with responsibilities evolving to meet business needs and enable individual growth.

Requirements
  • Top Secret security clearance
  • High school graduation or GED. High-level education, such as a technical bachelor's degree, is highly valued but not required.
  • At least 8 years of IT experience, with at least a year working directly with Splunk, either as a power user or as a system administrator.
  • Experience with the Department of Defense or other federal agencies is preferred but not required.
  • Hold an industry certification related to any of the following technologies: Windows OS, Red Hat Enterprise Linux, Microsoft Azure, Amazon Web Services, or VMWare. Other industry certifications may also be applicable for this position and will be considered upon request.
  • Experience with scripting languages such as bash, python and powershell.
  • Broad understanding of IT infrastructure, including network, system, application and compliance, and corresponding logs generated.
  • Splunk Enterprise Certified Admin certification strongly preferred. If the successful candidate does not already hold this certification at the time of hire, he/she will be expected to obtain it within 6 months of starting
  • CompTIA Security+ or equivalent certification required, either at the time of hire or within 6 months of starting if not already held.


Similar Jobs

More Jobs at Core4ce

More Aerospace & Defense Jobs

Find similar Sr. Splunk Administrator jobs: