Solution Architect: Sr Splunk Engineer

Chenega CorporationArlington, VA
Onsite

About The Position

The Senior Splunk Engineer is responsible for developing, maintaining, and optimizing the enterprise SIEM infrastructure with a strong focus on log correlation, alerting, and operational dashboards. This role combines Splunk expertise with advanced network awareness to drive threat detection, baselining, and event correlation across enterprise and air-gapped environments. The ideal candidate collaborates closely with network engineers, threat analysts, and Extra Hop SMEs to interpret packet-level data and refine alert logic for mission-focused visibility.

Requirements

  • Bachelors degree in a related field OR Associates degree with an additional 2+ years of relevant IT experience OR High school diploma or GED equivalent with an additional 4+ years of directly related IT experience in lieu of degree
  • 12+ years of cybersecurity or network engineering experience with 3+ years of Splunk engineering and content development
  • Hands-on experience with Splunk Enterprise and Enterprise Security (ES) in air-gapped or mission-secure environments
  • Must hold a current DoD 8140 (or 8570) baseline certification at the IAT Level II or higher (e.g., CompTIA Security+)
  • U.S. Citizen with active TS/SCI clearance.
  • Expert-level Splunk SPL development and content creation
  • Strong understanding of TCP/IP, packet structures, and network traffic analysis
  • Familiarity with Extra Hop, SolarWinds, and PCAP-based threat identification
  • Ability to correlate multi-source logs with behavioral and network data to create high-fidelity detections
  • Experience tuning and normalizing data to align with Splunk CIM and ES frameworks
  • Proficiency with regex, lookup tables, macros, and dashboard visualizations
  • Excellent documentation and mentoring skills
  • Comfortable working across cyber, networking, and threat teams to improve detection and visibility

Responsibilities

  • Lead the design and optimization of Splunk dashboards, alerts, correlation searches, and data ingestion for security and network observability
  • Collaborate with network and Extra Hop teams to integrate flow data, traffic patterns, and anomalies into actionable Splunk detections
  • Support development of network baseline visualizations and identify deviations using correlated log and traffic data
  • Tune log sources and ingestion pipelines to improve performance, reduce false positives, and enhance signal fidelity
  • Develop and manage Splunk content related to firewalls, VPNs, proxies, routers, switches, and endpoint devices
  • Work with analysts to interpret detection triggers in context of network flows, packet captures, and behavior anomalies
  • Configure and maintain Splunk components including apps, indexes, forwarders, and CIM data models
  • Produce documentation, runbooks, and training for SOC teams and technical stakeholders
  • Operate in both connected and disconnected environments; support secure enclave deployments of Splunk
  • Mentor junior engineers and analysts in SPL, dashboarding, and detection development
  • Other duties as assigned

Benefits

  • professional development is embedded in their core culture
  • opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world
  • on-the-job learning experiences
  • formal development programs
  • well-being programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service