- Job type
- Full-time
- Work mode
- On-site
- Level
- Not listed
- Department
- Information Technology
- Experience
- 3+ years experience
- Posted
- Aug 26, 2026
About the role
SMX is seeking a Splunk Enterprise Administrator who will be responsible for architecting, deploying, configuring, maintaining, and optimizing an enterprise-scale Splunk Enterprise and Splunk Enterprise Security (ES) environment. This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the Splunk infrastructure. The Administrator ensures high availability, data integrity, and peak search performance across distributed Splunk topologies. The scope of this position includes an Army Intelligence security domain as defined by the Cybersecurity Director. Additionally, the Splunk Administrator is responsible for ensuring ICS 500-27 audit compliance and collaborating closely with cyber analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.
Essential Duties & Responsibilities
- Splunk Infrastructure Management: Install, configure, upgrade, and administer multi-site distributed Splunk Enterprise topologies, including Indexer Clusters, Search Head Clusters (SHC), Deployment Servers, Heavy/Universal Forwarders (UF), and Technology Add-ons (TAs).
- Enterprise Security (ES) Operations: Maintain Splunk ES frameworks, ensure Common Information Model (CIM) compliance, manage correlation searches, configure Risk-Based Alerting (RBA), and maintain threat intelligence feeds and lookup tables.
- Linux System Administration: Perform OS-level configuration, storage provisioning, kernel tuning, and automation across underlying Red Hat Enterprise Linux (RHEL) / CentOS systems hosting Splunk components.
- Advanced SPL Development: Design, optimize, and maintain complex Search Processing Language (SPL) queries, macros, and scheduled searches to minimize resource utilization and index scanning overhead.
- Dashboards & Reporting: Build and customize operational dashboards, executive posture summaries, and tactical analytics views for SOC analysts, incident response teams, and leadership.
- High Availability & Clustering: Maintain resilient multi-site indexer replication and search head clustering to prevent data loss and ensure uninterrupted operational visibility.
- Disaster Recovery (DR): Develop, document, and regularly validate disaster recovery procedures, cold/warm backup pipelines, and rapid restoration protocols.
- SLA & Ingest Monitoring: Establish automated health monitoring, alerting, and metric dashboards to identify data feed drop-offs, ingestion lag, forwarder heartbeat failures, and pipeline bottlenecks on high-impact systems.
- STIG Implementation: Ensure rigorous Security Technical Implementation Guide (STIG) compliance and continuous vulnerability remediation across all Splunk software, apps, and host operating systems.
- Architecture Documentation: Maintain comprehensive data flow diagrams, system architectural schematics, hardware/software baselines, standard operating procedures (SOPs), and log onboarding registries.
- Troubleshooting and Performance Tuning:
- Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.
- Optimize queries, alerts, and settings to lower resource use and improve efficiency.
- Resolve data ingestion and indexing issues.
Required Skills, Experience & Education
- Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for CI Poly).
- Certifications:
- Splunk Enterprise Administrator
- Security+ (or above)
- Education
- Bachelor’s degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.
- Technical Skills
- 3-5 years of hands-on experience installing, configuring, administering, and tuning distributed Splunk Enterprise and Splunk Enterprise Security environments.
- Proficiency in managing Splunk components including forwarders, indexers, and search heads.
- Strong understanding of SPL and the capacity to create custom dashboards and reports.
- Experience in data parsing, field extraction, and indexing.
Desired Skills/Experience
- Experience transitioning a SIEM environment from Splunk to Elastic
- Experience supporting Splunk Enterprise Security (ES).
- Familiarity with scripting languages (e.g., Python, Bash) for automation.
- Knowledge of security operations, including Splunk best practices.
Proposed Salary
The proposed salary for this position is $160,000 — $190,000 USD.