SIEM Engineer (5384) (TS/SCI) (Ft. Meade, MD)

Reposted 7 Days Ago
Be an Early Applicant
Fort Meade, MD, USA
In-Office
160K-190K Annually
Senior level
Cloud • Information Technology
The Role
Implement, configure, and manage enterprise SIEMs, lead migration from Splunk to Elastic, onboard data sources, build/optimize searches, dashboards and alerts, ensure RMF/STIG compliance, maintain HA/DR and SLA targets, and collaborate with analysts and architects to support real-time security monitoring and incident response.
Summary Generated by Built In

SMX is seeking a Security Information and Event Management (SIEM) Engineer responsible for implementing, configuring, and managing SIEM environments to support the organization’s data analytics, security, and operational goals. This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the SIEM infrastructure. The scope of this position includes all Army Intelligence security domains as defined by the Cybersecurity Director, and the Engineer will verify that all solutions and configurations meet the required security standards and compliance requirements. Additionally, the SIEM Engineer is responsible for ensuring ICS 500-27 audit compliance, maintaining the integrity and security of the SIEM system, and collaborating closely with analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.

This is a full-time onsite position in Ft. Meade, MD.

Essential Duties & Responsibilities

  • SIEM Platform Migration (Splunk to Elastic)

  • Lead the end-to-end migration of the enterprise Security Information and Event Management (SIEM) capability from Splunk to the Elastic Stack (Elasticsearch, Logstash, Kibana), including planning, stakeholder coordination, execution, and post-migration validation to ensure zero degradation in security monitoring and detection coverage.

  • Develop and manage the migration roadmap and program schedule, defining phased cutover milestones, resource requirements, and risk mitigation strategies while ensuring parallel operation of both platforms during transition to maintain continuous threat detection and incident response readiness.

  • Splunk Implementation and Maintenance:
    • Set up and configure Splunk instances, including forwarders, indexers, and search heads.
    • Onboard new data sources into Splunk while ensuring proper parsing, field extraction, and indexing.
    • Manage Splunk licenses, user access controls, and configurations to maintain stability and security. 
  •  Data Analysis and Visualization:
    • Build and optimize dashboards, alerts, and reports for security monitoring, IT operations, and business use cases.
    • Develop and enhance Splunk Search Processing Language (SPL) queries to facilitate advanced analytics.
    • Collaborate with teams to ensure that data sources meet the requirements for analysis and visualization.
  • Troubleshooting and Performance Tuning:
    • Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.
    • Optimize queries, alerts, and settings to lower resource use and improve efficiency.
    • Resolve data ingestion and indexing issues.
  • Service Level Agreement (SLA) Management and Monitoring: •
    • Maintain and monitor the Service Level Agreement (SLA) of the Splunk system, ensuring that the system meets the required uptime, performance, and data ingestion targets.
    • Monitor the ingest of data sources, particularly high-value or high-impact systems, and alert stakeholders when these systems stop sending events or experience disruptions.
    • Develop and implement monitoring dashboards and alerts to quickly identify and respond to SLA breaches or data ingest issues.
  •  Disaster Recovery and High Availability:
    • Design and implement disaster recovery and high availability solutions for the Splunk system, ensuring minimal downtime and data loss in the event of a disaster or system failure.
    • Develop and maintain disaster recovery plans, including backup and restore procedures, to ensure business continuity.
    • Configure and manage Splunk clustering, replication, and indexing to ensure high availability and redundancy.
  • Compliance and Security:
    • Maintain RMF (Risk Management Framework) ATO (Authority to Operate) compliance for the Splunk system, ensuring that all security controls and configurations are in place and up-to-date.
    • Ensure STIG (Security Technical Implementation Guide) compliance for the Splunk system, including configuration and vulnerability management.
    • Maintain accurate and up-to-date documentation, including:
    • Data flow diagrams to illustrate data ingestion and processing.
    • Architecture diagrams to depict the Splunk system architecture.
    • System inventories to track hardware and software components.
    • Collaborate with the security team to ensure that the Splunk system meets all relevant security requirements and standards.
  •  SIEM Management:
    • Manage the onboarding process for new systems and log types, including:
    • Maintaining onboarding documents for each system/log type.
    • Developing and maintaining a detailed list of event codes per operating system and application type.
    • Ensure that all data sources are properly configured and sending events to the Splunk system.
    • Collaborate with analysts and architects to develop and implement use cases for security monitoring and incident response.
  •  Collaboration and Support:
    • Collaborate with architects and analysts to create and implement solutions that align with the organization’s objectives.
    • Provide technical support and assist end users with Splunk-related issues, ensuring timely resolution and minimal downtime.
  •  Documentation and Continuous Improvement:
    • Document the configurations, workflows, and troubleshooting procedures to enhance team knowledge sharing.
    • Research and suggest enhancements to Splunk infrastructure and analytics capabilities.

Required Skills, Experience & Education

  • Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for SAP and CI Poly).
  • Certifications:
    • Splunk Enterprise Certified Architect
    • Security+ (or above)
  • Education
    • Bachelor’s degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.
  • Technical Skills
    • 2-3 years of experience an Elastic SIEM environment
    • Proficiency in managing Splunk components including forwarders, indexers, and search heads.
    • Strong understanding of SPL and the capacity to create custom dashboards and reports.
    • Experience in data parsing, field extraction, and indexing.

Desired Skills/Experience

  • Experience transitioning a SIEM environment from Splunk to Elastic
  • Experience supporting Splunk Enterprise Security (ES) or IT Service Intelligence (ITSI).
  • Familiarity with scripting languages (e.g., Python, Bash) for automation.
  • Knowledge of security operations, including SIEM best practices.

Application Deadline: September 7, 2026

#CJPOST

#LI-onsite



The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.

The proposed salary for this position is:
$160,000$190,000 USD

At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.

We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.

SMX is an Equal Opportunity employer including disabilities and veterans.

Selected applicant may be subject to a background investigation and/or education verification.

SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Skills Required

  • Active Top Secret (TS) security clearance with SCI eligibility and NATO read-on; willingness for SAP and CI Poly
  • Splunk Enterprise Certified Architect certification
  • Security+ or higher certification
  • Bachelor's degree in Computer Science, Information Technology, or similar OR minimum 5 years experience working with Splunk (installation, configuration, management)
  • 2-3 years experience in an Elastic SIEM environment
  • Proficiency managing Splunk components (forwarders, indexers, search heads)
  • Strong understanding of Splunk Search Processing Language (SPL) and ability to create custom dashboards and reports
  • Experience with data parsing, field extraction, and indexing for SIEM ingestion

SMX Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SMX and has not been reviewed or approved by SMX.

  • Fair & Transparent Compensation Salary ranges are publicly listed on many postings and a pay transparency statement clarifies how location, contract, and credentials influence offers. This visibility helps set clear expectations around compensation.
  • Leave & Time Off Breadth About four weeks of PTO plus 11 paid federal holidays are highlighted in careers materials. Paid military leave on some roles further expands time‑off coverage.
  • Retirement Support A 401(k) with a dollar‑for‑dollar match on the first 5% and immediate vesting is called out in role descriptions. Traditional and Roth options support long‑term savings.

SMX Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hollywood, MD
1,413 Employees
Year Founded: 1995

What We Do

SMX is a global technology and advanced engineering provider specializing in Cloud Solutions, C5ISR, and Advanced Engineering / IT. Our tradition of delivering innovative, technical solutions dates back to 1995, however, you may know us better by one of our legacy company names: Trident Technologies, Smartronix, Datastrong, or C2S Consulting Group. With the support of OceanSound Partners, our private equity investment sponsor, we began operating as one business starting in 2019 and became SMX in 2021. We operate in close proximity to our clients around the globe and have core locations in Alabama, California, the DC Metro, Florida, Hawaii, Maryland, and Massachusetts. Today, as SMX, we are one team and together empower government and commercial enterprises to become more effective, innovative, and resilient, no matter what challenges they face. SMX offers competitive benefits, excellent work environments, and growth opportunities for our employees while continuing to expand operations and support our communities. We have more than 25 years of rapid and consistent growth with continuous recognition as an employer-of-choice technology company. In addition, we have earned coveted industry quality and business certifications; have a strong commitment to business partnerships, ethics, compliance, and sustainability; and have a multitude of premier contracting vehicles. The combination of these attributes allows us to provide sound, repeatable business solutions yet remain flexible and agile to quickly adapt to specific customer requirements. Committed to ensuring the highest levels of customer satisfaction, SMX is structured around the programs and technologies we support to provide optimal and seamless operations. We have maintained a reputation for excellence, helping to assure the missions of our Department of Defense, Public Sector, Fortune 1000, and other Government and commercial customers.

Similar Jobs

PwC Logo PwC

Salesforce Consulting Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
64 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

ServiceNow Deployment- Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
62 Locations
370000 Employees
99K-232K Annually

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
8 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account