Splunk Enterprise Administrator (5552) (TS/SCI) (Ft. Meade, MD)

Posted One Month Ago
Be an Early Applicant
Fort Meade, MD, USA
In-Office
160K-190K Annually
Senior level
Cloud • Information Technology
The Role
Implements, configures, and manages Splunk and Elastic SIEM environments, including leading the migration from Splunk to Elastic. Responsibilities include data-source onboarding, SPL query optimization, dashboards, alerts, reporting, performance tuning, high availability, disaster recovery, SLA monitoring, troubleshooting, documentation, and RMF, ATO, STIG, and audit compliance. The engineer collaborates with analysts and architects to support security monitoring, incident response, and real-time visibility across Army Intelligence security domains.
Summary Generated by Built In

SMX is seeking a Splunk Enterprise Administrator who will be responsible for architecting, deploying, configuring, maintaining, and optimizing an enterprise-scale Splunk Enterprise and Splunk Enterprise Security (ES) environment.  This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the Splunk infrastructure. The Administrator ensures high availability, data integrity, and peak search performance across distributed Splunk topologies. The scope of this position includes an Army Intelligence security domain as defined by the Cybersecurity Director. Additionally, the Splunk Administrator is responsible for ensuring ICS 500-27 audit compliance and collaborating closely with cyber analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.

This is a full-time onsite position in Ft. Meade, MD.

Essential Duties & Responsibilities

  • Splunk Infrastructure Management: Install, configure, upgrade, and administer multi-site distributed Splunk Enterprise topologies, including Indexer Clusters, Search Head Clusters (SHC), Deployment Servers, Heavy/Universal Forwarders (UF), and Technology Add-ons (TAs).
  • Enterprise Security (ES) Operations: Maintain Splunk ES frameworks, ensure Common Information Model (CIM) compliance, manage correlation searches, configure Risk-Based Alerting (RBA), and maintain threat intelligence feeds and lookup tables.
  • Linux System Administration: Perform OS-level configuration, storage provisioning, kernel tuning, and automation across underlying Red Hat Enterprise Linux (RHEL) / CentOS systems hosting Splunk components.
  • Advanced SPL Development: Design, optimize, and maintain complex Search Processing Language (SPL) queries, macros, and scheduled searches to minimize resource utilization and index scanning overhead.
  • Dashboards & Reporting: Build and customize operational dashboards, executive posture summaries, and tactical analytics views for SOC analysts, incident response teams, and leadership.
  • High Availability & Clustering: Maintain resilient multi-site indexer replication and search head clustering to prevent data loss and ensure uninterrupted operational visibility.
  • Disaster Recovery (DR): Develop, document, and regularly validate disaster recovery procedures, cold/warm backup pipelines, and rapid restoration protocols.
  • SLA & Ingest Monitoring: Establish automated health monitoring, alerting, and metric dashboards to identify data feed drop-offs, ingestion lag, forwarder heartbeat failures, and pipeline bottlenecks on high-impact systems.
  • STIG Implementation: Ensure rigorous Security Technical Implementation Guide (STIG) compliance and continuous vulnerability remediation across all Splunk software, apps, and host operating systems.
  • Architecture Documentation: Maintain comprehensive data flow diagrams, system architectural schematics, hardware/software baselines, standard operating procedures (SOPs), and log onboarding registries.
  • Troubleshooting and Performance Tuning:
    • Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.
    • Optimize queries, alerts, and settings to lower resource use and improve efficiency.
    • Resolve data ingestion and indexing issues.

Required Skills, Experience & Education

  • Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for CI Poly).
  • Certifications:
    • Splunk Enterprise Administrator
    • Security+ (or above)
  • Education
    • Bachelor’s degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.
  • Technical Skills
    • 3-5 years of hands-on experience installing, configuring, administering, and tuning distributed Splunk Enterprise and Splunk Enterprise Security environments.
    • Proficiency in managing Splunk components including forwarders, indexers, and search heads.
    • Strong understanding of SPL and the capacity to create custom dashboards and reports.
    • Experience in data parsing, field extraction, and indexing.

Desired Skills/Experience

  • Experience transitioning a SIEM environment from Splunk to Elastic
  • Experience supporting Splunk Enterprise Security (ES).
  • Familiarity with scripting languages (e.g., Python, Bash) for automation.
  • Knowledge of security operations, including Splunk best practices.

Application Deadline: October 19, 2026

#CJPOST

#LI-onsite



The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.

The proposed salary for this position is:
$160,000—$190,000 USD

At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.

We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.

SMX is an Equal Opportunity employer including disabilities and veterans.

Selected applicant may be subject to a background investigation and/or education verification.

SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Skills Required

  • Active Top Secret security clearance with eligibility for SCI and NATO read-on before starting work
  • Willingness to obtain SAP and CI Poly access
  • Splunk Enterprise Certified Architect certification
  • Security+ certification or higher
  • Bachelor's degree in computer science, information technology, or a similar field, or at least 5 years of Splunk experience
  • 2-3 years of experience in an Elastic SIEM environment
  • Experience managing Splunk forwarders, indexers, and search heads
  • Proficiency with SPL and creating custom dashboards and reports
  • Experience with data parsing, field extraction, and indexing
  • Experience transitioning a SIEM environment from Splunk to Elastic
  • Experience supporting Splunk Enterprise Security or IT Service Intelligence
  • Familiarity with Python or Bash scripting for automation
  • Knowledge of security operations and SIEM best practices

SMX Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SMX and has not been reviewed or approved by SMX.

  • Fair & Transparent Compensation — Salary ranges are publicly listed on many postings and a pay transparency statement clarifies how location, contract, and credentials influence offers. This visibility helps set clear expectations around compensation.
  • Leave & Time Off Breadth — About four weeks of PTO plus 11 paid federal holidays are highlighted in careers materials. Paid military leave on some roles further expands time‑off coverage.
  • Retirement Support — A 401(k) with a dollar‑for‑dollar match on the first 5% and immediate vesting is called out in role descriptions. Traditional and Roth options support long‑term savings.

SMX Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hollywood, MD
1,413 Employees
Year Founded: 1995

What We Do

SMX is a global technology and advanced engineering provider specializing in Cloud Solutions, C5ISR, and Advanced Engineering / IT. Our tradition of delivering innovative, technical solutions dates back to 1995, however, you may know us better by one of our legacy company names: Trident Technologies, Smartronix, Datastrong, or C2S Consulting Group. With the support of OceanSound Partners, our private equity investment sponsor, we began operating as one business starting in 2019 and became SMX in 2021. We operate in close proximity to our clients around the globe and have core locations in Alabama, California, the DC Metro, Florida, Hawaii, Maryland, and Massachusetts. Today, as SMX, we are one team and together empower government and commercial enterprises to become more effective, innovative, and resilient, no matter what challenges they face. SMX offers competitive benefits, excellent work environments, and growth opportunities for our employees while continuing to expand operations and support our communities. We have more than 25 years of rapid and consistent growth with continuous recognition as an employer-of-choice technology company. In addition, we have earned coveted industry quality and business certifications; have a strong commitment to business partnerships, ethics, compliance, and sustainability; and have a multitude of premier contracting vehicles. The combination of these attributes allows us to provide sound, repeatable business solutions yet remain flexible and agile to quickly adapt to specific customer requirements. Committed to ensuring the highest levels of customer satisfaction, SMX is structured around the programs and technologies we support to provide optimal and seamless operations. We have maintained a reputation for excellence, helping to assure the missions of our Department of Defense, Public Sector, Fortune 1000, and other Government and commercial customers.

Similar Jobs

Zeta Global Logo Zeta Global

Director of Paid Search, EDU

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
120K-140K Annually

Imprivata Logo Imprivata

Senior Project Manager

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
141K-153K Annually

SoFi Logo SoFi

Senior Manager, AML Financial Intelligence Unit - Digital Assets

Fintech • Mobile • Software • Financial Services
Easy Apply
Remote or Hybrid
United States
4500 Employees
141K-242K Annually

Pfizer Logo Pfizer

Specialty Care Patient Engagement Go-To-Market Excellence Director

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
2 Locations
121990 Employees
177K-294K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account