Senior SIEM Engineer - Splunk

Posted Yesterday
Be an Early Applicant
Washington, DC, USA
In-Office
145K-155K Annually
Senior level
Artificial Intelligence • Cybersecurity • Quantum Computing • Defense
The Role
Owns the architecture, strategy, scalability, and long-term health of the organization’s Splunk SIEM. Leads detection engineering, data onboarding, platform optimization, upgrades, integrations, threat hunting, compliance support, and incident-response investigations. The role mentors engineers and SOC analysts, serves as the escalation point for complex issues, reports security metrics to leadership, and partners on security architecture and response planning.
Summary Generated by Built In
Description

Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operates with autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy. The senior engineer is the escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents. 

Responsibilities 

  • Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (including SmartStore where applicable) strategy 
  • Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage 
  • Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance 
  • Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems) 
  • Optimize search performance and indexing strategy to manage license usage and infrastructure cost at scale 
  • Mentor and provide technical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices 
  • Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunk expertise 
  • Evaluate and recommend new Splunk apps, premium solutions, or architectural changes 
  • Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency) 
  • Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions 
  • Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST) 
  • Represent the SIEM/detection function in cross-functional security architecture and incident response planning 
Qualifications

Required:

  • Bachelor’s Degree required (experience and education equivalents are considered and can be substituted for a Bachelor’s Degree. 
  • 8 years of general work experience with 6 years relevant “functional” experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments 
  • Advanced proficiency in SPL, including complex correlation searches, data models, and search optimization for large-scale environments 
  • Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed 
  • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling 
  • Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches 
  • Strong scripting/automation skills (Python, PowerShell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use) 
  • Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons 
  • Track record of leading or significantly contributing to incident response investigations 
  • Familiarity with compliance frameworks relevant to the organization's industry 
  • Relevant certifications preferred: Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP 

Desired:

  • Experience with Splunk in a VMware ESXi, vCenter virtual infrastructure 
  • Experience or working knowledge with similar SIEM tools 

Clearance:

  • An active Top Secret clearance with SCI eligibility is required.

Location and Schedule:

  • This position is onsite at the customer location in Washington, DC. The environment requires onsite support five days per week, with some flexibility in scheduling based on program and customer requirements. Core business hours are 8am-4pm.
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $145,000-$155,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 


At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 


Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Skills Required

  • Bachelor's degree, or equivalent combination of education and experience
  • 8 years of general work experience
  • 6 years of relevant functional experience in security operations or detection engineering
  • Substantial hands-on Splunk ownership, including experience in distributed or clustered environments
  • Advanced proficiency in SPL, including complex correlation searches, data models, and search optimization
  • Deep knowledge of Splunk architecture, including indexer and search head clustering, forwarder management, and index design
  • Working knowledge of Splunk Enterprise Security
  • Strong understanding of MITRE ATT&CK, the cyber kill chain, and threat modeling
  • Experience designing Splunk detection strategies
  • Strong scripting and automation skills using Python and PowerShell
  • Familiarity with SOAR platform integration
  • Experience with cloud security monitoring using AWS, Azure, or GCP log sources
  • Experience with Splunk cloud-specific add-ons
  • Experience leading or significantly contributing to incident response investigations
  • Familiarity with relevant compliance frameworks
  • Experience with Splunk in VMware ESXi and vCenter virtual infrastructure
  • Experience or working knowledge with similar SIEM tools
  • Relevant certifications such as Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
969 Employees
Year Founded: 2018

What We Do

Quantum Sky is a Reston, Virginia-based mission technology company, formerly Tyto Athene, that delivers secure, AI-enabled and quantum-ready capabilities to defense, intelligence, and federal civilian agencies. Its work spans enterprise IT, network engineering, cybersecurity, cloud, software, post-quantum cryptography, and applied quantum technologies, helping customers modernize critical systems, protect mission data, and achieve faster, more resilient decision-making across complex, high-consequence missions.

Similar Jobs

Vestmark, Inc. Logo Vestmark, Inc.

Senior Trader

Fintech • Software
Easy Apply
Remote or Hybrid
United States
400 Employees
100K-115K Annually

Nasuni Logo Nasuni

Operations Analyst

Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Easy Apply
Remote or Hybrid
United States
550 Employees

Sprinter Health Logo Sprinter Health

Medical Auditor - Remote

Artificial Intelligence • Healthtech • Logistics • Social Impact • Software • Telehealth
Remote or Hybrid
United States
500 Employees
33-33 Hourly

HiBob Logo HiBob

Broker Partner Manager - PST

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
US
1350 Employees
136K-170K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account