Splunk EnterpriseSplunk CloudSplunk Enterprise Security (ES)IT Service Intelligence (ITSI)Splunk Search Processing Language (SPL)Syslog
Full Job Posting
Lead the deployment and configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring scalability, high availability, and compliance with federal IT standards.
Create custom dashboards, reports, and alerts to support security operations, system monitoring, and compliance reporting.
Ingest and normalize data from diverse sources (e.g., syslogs, APIs, cloud services) using props, transforms, and field extractions.
Collaborate with cybersecurity teams to develop correlation searches, threat detection use cases, and support incident response efforts aligned with NIST and other federal frameworks.
Provide technical guidance to junior engineers and maintain thorough documentation of configurations, processes, and best practices.
Active Top Secret Clearance with the ability to pass a Lifestyle Polygraph
Bachelor's Degree in Physics, Mathematics, Information Technology, Computer Science, Business, or related discipline
Eight years of relevant professional experience of applicable technology expertise.
Proficient in designing, implementing, and managing Splunk environments, including cluster architecture.
Advanced knowledge of Splunk Search Processing Language (SPL)
Expertise in developing complex queries, dashboards, and reports using SPL.
Ability to optimize searches for performance and scalability.
Strong experience in data onboarding, parsing, and indexing, including log management and extraction of meaningful metrics.
Familiar with various data input methods like Syslog, HTTP Event Collectors (HEC), and APIs.
Knowledge of Splunk Enterprise Security (ES) and/or IT Service Intelligence (ITSI)
Experience in configuring and managing Splunk ES and /or ITSI modules.
Understanding of security information and event management (SIEM) concepts.
Proficiency with REST APIs and other scripting tools (e.g. Python, Bash) to automate tasks and integrations.
In-depth knowledge of Linux/Unix systems administration, including shell scripting and performance tuning.
Familiarity with cloud platforms (AWS and/or Azure) and experience managing Splunk in cloud environments.
Ability to troubleshoot and resolve Splunk performance issues.
Experience with scaling Splunk in large environments and ensuring high availability.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Xpect Solutions, LLC is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications.
Our talented staff are the key to our success.
They bring the knowledge, experience and technical skills to deliver the best solutions to our customers.
We support our team by providing open communication, win-win partnerships with clients and vendors, a team-oriented culture, and a focus on professional development and growth for a long-lasting and happy career.
We offer a benefits package that is designed to keep our most important assets – our employees – healthy, happy, energized and moving forward.
Our philosophy is simple – empower our employees with the benefits, resources and the financial incentives they need to be successful.
Benefits And Perks
A competitive Medical, Dental, and Vision plan
• Retirement Savings Plan
Life Insurance
AD&D Insurance
Short Term and Long Term Disability Insurance
3 weeks of annual PTO
11 days of Holiday PTO
Performance Awards
Referral Bonus Plan (of up to $5,000/year)
Education Reimbursement/Training (of up to $2,500/year)
About XPECT Solutions, LLC
Software & SaaS126 employeesFounded 2004
U.S. systems integrator delivering enterprise IT, cybersecurity, cloud, network, data-center, and physical-security solutions to federal agencies.