About this opportunity
Quantum Sky lists this Senior SIEM Engineer (Splunk) opportunity in washington, District of Columbia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operates with autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy. The senior engineer is the escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents.
Responsibilities
Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (including SmartStore where applicable) strategy
Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage
Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance
Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems)
Optimize search performance and indexing strategy to manage license usage and infrastructure cost at scale
Mentor and provide technical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices
Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunk expertise
Evaluate and recommend new Splunk apps, premium solutions, or architectural changes
Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency)
Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions
Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST)
Represent the SIEM/detection function in cross-functional security architecture and incident response planning
Required:
Bachelor’s Degree required (experience and education equivalents are considered and can be substituted for a Bachelor’s Degree.
8 years of general work experience with 6 years relevant “functional” experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments
Advanced proficiency in SPL, including complex correlation searches, data models, and search optimization for large-scale environments
Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed
Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling
Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches
Strong scripting/automation skills (Python, PowerShell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use)
Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons
Track record of leading or significantly contributing to incident response investigations
Familiarity with compliance frameworks relevant to the organization's industry
Relevant certifications preferred: Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP
Experience with Splunk in a VMware ESXi, vCenter virtual infrastructure
Experience or working knowledge with similar SIEM tools
Clearance:
An active Top Secret clearance with SCI eligibility is required.
Location and Schedule:
This position is onsite at the customer location in Washington, DC. The environment requires onsite support five days per week, with some flexibility in scheduling based on program and customer requirements. Core business hours are 8am-4pm.
#J-18808-Ljbffr
Worksite address
washington, DC, 20022, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.