Continuous Monitoring Team Lead (Splunk)

SAICArlington, VA
Hybrid

About The Position

The Continuous Monitoring Team Lead (Splunk) is a critical SME role working across Splunk, ServiceNow, and supporting security platform technologies to build analytic maturity and integrations with SOAR, UEBA, and Zero Trust Architecture. Mature analytics and normalized data will support 10+ cyber teams who are also working with other task areas that handle customer relationships, service portfolio and catalog management, software engineering & development, data/AI engineering, IT systems operations, and use case intake and analytics for DoW enterprise-scale mission objectives expected in Spring/Summer 2026. Positions are contingent pending contract award. The work will be performed in the Alexandria, Virginia. Some work may be performed remotely, subject to Government approval.

Requirements

  • Splunk expertise
  • ServiceNow expertise
  • Experience with SOAR platforms
  • Experience with UEBA capabilities
  • Experience with Zero Trust Architecture
  • Experience with data normalization strategies (field extractions, CIM alignment, data model optimization)
  • Experience with AI/ML-driven analytics
  • Experience with threat intelligence
  • Experience with cybersecurity analytics

Responsibilities

  • Lead the Continuous Monitoring Team in designing, building, and maturing enterprise cybersecurity analytics across Splunk, supporting continuous monitoring objectives across all CSP/security enclaves.
  • Architect and develop advanced Splunk use cases, dashboards, and custom applications to enable proactive detection, visibility, and decision support for 10+ cyber teams.
  • Design and implement data normalization strategies, including field extractions, CIM alignment, and data model optimization to improve analytic fidelity and reuse.
  • Integrate Splunk with ServiceNow, SOAR platforms, UEBA capabilities, and Zero Trust Architecture to enable automated workflows and enriched operational context.
  • Identify and close visibility gaps by engineering new analytics, correlations, and data onboarding strategies to enhance enterprise monitoring coverage.
  • Collaborate with data/AI engineering teams to incorporate AI/ML-driven analytics, automation, and intelligent alerting into Splunk-based monitoring solutions.
  • Evaluate and optimize data quality, ingestion pipelines, and telemetry sources to ensure high-confidence analytics and reduced false positives.
  • Develop reusable analytic content and patterns based on threat intelligence, lessons learned, and evolving mission requirements, enabling other teams to scale detection and monitoring capabilities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service