Splunk Administrator / SIEM Analyst
We are seeking a Splunk Administrator / SIEM Analyst to support enterprise security monitoring, log ingestion, analytics, and incident response activities within a DISA-domain environment. The selected candidate will operate and administer Splunk and related SIEM/analytics platforms, support server and platform log onboarding, and help prepare analytics capabilities for OCI environments.
This role requires hands-on experience with SIEM administration, security analytics, incident response support, and scripting/automation across tools such as Splunk, Elastic, and other analytics platforms. Experience with WAF, identity systems such as OHS/OAM, and WebLogic is highly desired. PeopleSoft experience is not required, but candidates should understand logging, monitoring, and analytics relevant to enterprise application environments.
Location
Crystal City, VA - On-Site/Hybrid
Work Schedule
Must be available to support either:
- Day Shift: 0800–1600
- Swing Shift: 1600–0000
Key Responsibilities
- Administer, operate, and maintain Splunk and other SIEM/analytics platforms.
- Configure, monitor, and troubleshoot log ingestion pipelines from servers, applications, and enterprise platforms.
- Ensure reliable onboarding, normalization, and availability of security and operational logs.
- Develop and maintain searches, dashboards, alerts, reports, and analytics use cases.
- Support incident response (IR) activities through log analysis, event correlation, and investigative data support.
- Assist with tuning SIEM content to improve detection fidelity and reduce false positives.
- Support analytics and logging requirements associated with OCI readiness/preparation.
- Work within a DISA-domain environment and coordinate with stakeholders across security, infrastructure, and application teams.
- Support monitoring and analysis for technologies including WAF, identity/access management, OHS/OAM, and WebLogic.
- Create scripts and automation to improve SIEM administration, data onboarding, correlation, and reporting.
- Validate that server, application, and platform data sources are properly integrated into SIEM tools.
- Document configurations, data flows, standard procedures, and operational issues.