Splunk Administrator
Listed on 2026-01-04
-
IT/Tech
Cybersecurity, IT Support
Description
Job Title: Splunk Administrator
Location: Northern Virginia
Department: Cyber Security Services
Reports To: Management
FLSA Status: Full Time/Non-exempt
Apavo is at the forefront of cybersecurity, providing services to military, defense, and critical infrastructure industries. Joining the Apavo team means becoming part of a company rooted in the principles of quality, and communication. We value positive, candid interactions and the belief that everyone has valuable contributions to make. Apavo stands out for its commitment to a work-life balance and fostering a growth mindset among all team members.
If you are looking to make a meaningful impact in the cybersecurity world while growing professionally in a supportive environment, Apavo is the place for you?
To be successful in this position you need to be collaborative and willing to work within a team. While you will need to be a self-starter completing tasks on your own, working together is critical in this role. You will be interfacing with the government and senior staff. Therefore, you should be articulate in your communications because your opinion matters. You will need to explain technical intricacies in a way that is easily understood.
JobPurpose
The Splunk Administrator supports the organization's Splunk infrastructure, ensuring its stability, performance, and security compliance. The Splunk Admin will support a critical mission within the Department of Defense. In the role as a Splunk Admin, you are expected to design, implement, and maintain the Splunk environment, proactively identifying and resolving issues, onboarding new data sources, and creating insightful dashboards and reports.
The Splunk Admin is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection and conduct system level auditing and continuous monitoring against threats and vulnerabilities.
To be successful in this position, you need to be collaborative and able to lead a team. You will need to be a self-starter completing your tasks on your own, while supervising the tasks of others on shift. Working together is critical in this role. You will be interfacing with the Government and senior staff. Therefore, you should be articulate in your communications because your opinion matters.
You will need to explain technical intricacies in a way that is easily understood.
- Provide expertise as it relates to Splunk implementations. Recommend and support changes to Splunk deployments.
- Support Indexer Clustering, Search Head Clustering, and Forwarders.
- Monitor, troubleshoot, and analyze overall health of Splunk infrastructure to include daily indexing volume, search volume and performance, data source reporting, user activity reporting, and custom apps/dashboards/visualizations.
- Perform root cause analysis on any issues with recommendations. Implement tactical and strategic solutions to problems.
- Develop, manage, and maintain documents supporting Splunk architecture and operational processes.
- Data on-boarding techniques such as syslog, DB Connect (db Connect), Universal Forwarder (UF), HTTP Event Collector (HEC), and custom scripting.
- Express a working knowledge of Linux to include use cases supporting patching, SSL toolset, capacity planning, routing protocols, and firewall rules.
- SPL/Dashboard experience in support of user analytics, systems performance, security, and environmental health.
- Knowledge of Splunk Data Models and their management to include implementation, tuning, and data normalization.
- Familiarity with Defense Information Systems Agency (DISA) Security Technical Implementation Guidelines (STIGs) checklists applicable to each Non-classified or Secret Internet Protocol (IP) Router Network (NIPRNet, SIPRNet) network environment for all Splunk implementations.
- Implement/create report dashboard designs, automated custom email report notifications, report log data repositories for each environment that are specific to the following audiences:
Leadership & Executives;
Cybersecurity Staff; and System Administrators. - Identify, analyze, define, & coordinate user, client, and stakeholder needs and translate them into technical requirements.
- Support day-to-day technical communication systems and incident tickets in support of operations.
The Splunk Administrator is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies.
Requirements Qualifications- 5+ years of overall demonstrated experience in cybersecurity, information assurance or computer science.
- Minimum 5 years of experience with Splunk.
- DoD Top Secret Clearance with SCI/ SAP eligibility is required.
- Bachelors degree…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).