Splunk Cyber Security SME
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, IT Support
Splunk Cyber Security SME - (Remote)
OverviewGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
RoleUSPS is seeking an experienced Splunk Subject Matter Expert with strong engineering skills to join our dynamic team. The ideal candidate will be responsible for designing, deploying, and maintaining on-premises and cloud-based Splunk environments to support enterprise-level monitoring, alerting, and reporting. This role demands deep expertise in Splunk system architecture, design, implementation, configuration and operational support in a hybrid on-prem Unix/Linux and cloud-based environment.
Candidates must be able to collaborate across Dev Ops, Security, and IT teams to optimize performance, ensure data integrity, system availability and support mission-critical operations. Proven hands-on experience with a large enterprise-wide Splunk environment is mandatory. Off-hours and weekend efforts for systems maintenance, upgrades and support may be required from time to time.
- Design, deploy, and maintain on-premises and cloud-based Splunk environments to support monitoring, alerting, and reporting.
- Collaborate across Dev Ops, Security, and IT teams to optimize performance, data integrity, and system availability.
- Provide operational support in a hybrid Unix/Linux environment and ensure scalability for enterprise-wide use.
- 5+ years of Splunk experience.
- Manage knowledge objects (fields, extractions, tags, event types, lookups, workflow actions, aliases, macros, etc.) and manage .conf/.cfg files across Splunk Enterprise versions.
- Experience with Splunk deployment and configuration management in large-scale environments.
- Proficiency in writing complex Splunk queries, dashboards, and alerts using SPL.
- Experience with REST APIs for Splunk and external system integration.
- Ability to analyze and troubleshoot complex data ingestion and parsing issues.
- Design and development of automation workflows and dashboards.
- Self-starter with a service-oriented mindset and ability to work independently to move projects forward.
- Strong problem-solving skills and ability to translate research into practical solutions.
- Strong communication and collaboration skills to convey technical concepts to technical and non-technical audiences.
- Experience mentoring and guiding junior researchers or team members.
- Ability to leverage the Splunk AI Assistant and other AI tools to increase accuracy and efficiency.
- Advanced knowledge of Unix/Linux and/or Windows systems administration and troubleshooting.
- Strong scripting skills in Bash, Python, JavaScript, SQL and Power Shell for automation and integration tasks.
- Experience with Splunk upgrades, patching, and performance tuning.
- Proficiency in integrating Splunk with cloud platforms (AWS, GCP, Azure).
- Understanding of security and compliance requirements and implementation of RBAC in Splunk.
- Strong knowledge of logging standards and best practices across application and infrastructure layers.
- Knowledge of defense-in-depth principles, network and security architecture, and IT device integrity.
- Experience with data onboarding and new projects.
- Familiarity with IT and cybersecurity standards (NIST, FISMA, FedRAMP).
- Experience with Splunk App for Data Science and Deep Learning.
- Experience with Splunk SOAR Automation toolset.
- Background in cybersecurity, systems/network administration, or observability.
- 8–12 years of relevant experience.
- Degree from an accredited college/university in an applicable field is required; if not in the applicable field, four additional years of related experience are required.
- Typically performs all functional duties independently.
- Special credentials (licenses and/or certifications) may be required at the Task Order level on a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).