Senior Splunk Administrator

GCyberWashington, DC

About The Position

GCYber is seeking a Senior Splunk Administrator to support a high-profile government customer. This is a hands-on administration role responsible for data ingestion, dashboard development, and resolving issues when data is missing, delayed, duplicated, or incorrectly parsed. As the Senior Splunk Administrator, you will administer and monitor an enterprise Splunk environment, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, deployers, cluster managers, and monitoring consoles. You will troubleshoot missing, delayed, duplicated, incorrectly parsed, or incorrectly routed data across the complete ingestion path. You will also configure and maintain Splunk inputs, outputs, indexes, sourcetypes, routing, filtering, timestamp extraction, and event parsing. Additionally, you will build and maintain Splunk dashboards, reports, alerts, and saved searches that provide useful operational and cybersecurity visibility. You will work with stakeholders to define dashboard requirements, identify the right data, and present results in a clear and actionable format. You will develop and optimize SPL searches that support dashboards, data validation, troubleshooting, trend analysis, and operational reporting. You will diagnose issues involving forwarders, blocked queues, certificates, network connectivity, indexing, permissions, dashboards, and search logic.

Requirements

  • Active DoD Top Secret/SCI clearance
  • Active IAT II certification (i.e., Security+, CySA+, CCNA-Security, GSEC, CND, GICSP, SSCP)
  • Bachelor’s Degree in Computer Science, Cybersecurity, Computer Engineering, Information Technology, or equivalent degree
  • 5+ years of Splunk administration or engineering experience.
  • Hands-on experience supporting a distributed enterprise Splunk environment
  • Experience with indexer clusters, search head clusters, heavy forwarders, universal forwarders, deployment servers, and related Splunk components.

Nice To Haves

  • Splunk certification preferred

Responsibilities

  • Administer and monitor an enterprise Splunk environment, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, deployers, cluster managers, and monitoring consoles.
  • Troubleshoot missing, delayed, duplicated, incorrectly parsed, or incorrectly routed data across the complete ingestion path.
  • Configure and maintain Splunk inputs, outputs, indexes, sourcetypes, routing, filtering, timestamp extraction, and event parsing.
  • Build and maintain Splunk dashboards, reports, alerts, and saved searches that provide useful operational and cybersecurity visibility.
  • Work with stakeholders to define dashboard requirements, identify the right data, and present results in a clear and actionable format.
  • Develop and optimize SPL searches that support dashboards, data validation, troubleshooting, trend analysis, and operational reporting.
  • Diagnose issues involving forwarders, blocked queues, certificates, network connectivity, indexing, permissions, dashboards, and search logic.

Benefits

  • 26 Days of Paid Leave + Annual PTO Increase
  • An extra day of paid leave for every year of employment with GCyber
  • Paid Parental Leave
  • Additional Leave Allowances for Military Duty, Jury Duty, and Bereavement Leave
  • 401(k) Matching
  • 100% Company-funded Disability Insurance
  • 90% Company-Funded Health, Dental, and Vision Insurance, with contributions to insurance benefits for spouses, children, and family members
  • Training and Professional Development Plans
  • Commuter Benefits Plan
  • Parking and Transportation Allowance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service