Senior Splunk SIEM/SOAR & Security Analytics/AI-ML Engineer at Technology & Bussiness Managment Inc.
Los Angeles, Los Angeles County, California, 90079, USA
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Security Management & Operations
Senior Splunk SIEM/SOAR & Security Analytics / AI-ML Engineer
Apply for Senior Splunk SIEM/SOAR & Security Analytics / AI-ML Engineer at Technology & Business Management, Inc. Remote, US.
This Full time on site position offers great opportunities for career growth.
Location & AvailabilityUS Based Position. Must be US Citizen.
Location:
Arlington VA (U.S.
-based). Remote Work Allowed in US.
Technology & Business Management, Inc. (TBM Inc.)
Required Experience8+ years in security analytics/SIEM engineering with 4+ years of advanced Splunk engineering; hands-on dashboarding, SPL, alerting, data onboarding, and automation required.
Position SummaryOwn DLP telemetry, analytics, dashboards, alerting, automation, and measurable optimization in Splunk, while supporting Government-approved SOAR/RPA and bounded AI/ML use cases.
Key Responsibilities- Engineer and maintain Splunk ingestion, normalization, searches, dashboards, reports, alerts, health metrics, event-volume trends, and operational/executive DLP reporting.
- Develop SPL queries and documented calculations that Government personnel can reproduce and sustain.
- Integrate telemetry from Symantec/Broadcom, Purview, Palo Alto, and other authorized DLP/security platforms.
- Design automated notifications, alerts, alarms, and Government-authorized SOAR/RPA workflows to reduce manual triage and improve response.
- Support event correlation, incident analytics, severity/prioritization, trend analysis, and detection-performance measurement.
- Evaluate approved AI/ML-enabled capabilities to reduce false positives, identify notable events, improve triage, and reduce analyst workload; establish baseline/candidate comparisons and rollback criteria.
- Track metrics such as false positives, false negatives where measurable, alert volume, time-to-triage/disposition, stability, workload, and business impact.
- Document data definitions, dashboard maintenance, automation logic, model/configuration tuning, test evidence, limitations, procedures, and Government training.
Splunk Enterprise / Splunk ES; SPL; dashboards; data models; alerts; field extraction; ingestion/onboarding; CIM; APIs; security analytics; incident correlation. Splunk SOAR or comparable orchestration/automation;
Python or scripting; REST APIs; JSON; data normalization. Understanding of DLP events/policies, SOC workflows, detection engineering, false-positive reduction, and security KPIs. Practical AI/ML analytics knowledge with emphasis on explainability, human review, validation, privacy/security controls, and measurable benefit rather than custom model research. Splunk Core Certified Power User/Admin/Architect or Splunk Enterprise Security certification strongly preferred.
Experience with Qmulos, federal continuous monitoring/FISMA reporting, or large federal Splunk environments. Experience integrating DLP products into SIEM/SOAR workflows. Current Public Trust/MBI or clearance.
EducationBachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Information Systems, or a related field is preferred. Equivalent directly relevant experience and advanced industry certifications may be considered, subject to the applicable contract labor-category requirements.
Federal Suitability / SecurityCandidate must be able to meet IRS personnel-security and suitability requirements for the position, including the applicable background investigation and required security/privacy training. A current favorably adjudicated federal Public Trust/MBI or other investigation that may qualify for reciprocity is highly desirable.
What Will Make a Candidate Stand OutDirect hands-on experience with the named platform(s), not only governance or oversight.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).