Splunk Engineer

CACIMclean, VA
Onsite

About The Position

CACI is seeking a highly motivated Splunk Engineer that has 8+ years of experience managing a Splunk Platform, creating Splunk applications, and using IT Service Intelligence (ITSI). The Splunk engineer will build applications to help manage, search, analyze, and visualize data. The role includes troubleshooting and performing Splunk application development following a Scrum Agile approach. The role also includes examining the existing environment for deficiencies and onboarding new data sources.

Requirements

  • TS/SCI Clearance with Counterintelligence Polygraph
  • BA/BS degree and 8 years of experience. In lieu of a bachelor’s degree 10 years of experience if AA/AS, or 12 additional years of experience with HS diploma
  • 8+ years of experience and demonstrated knowledge supporting IT Systems
  • 4+ years of experience implementing and operating Splunk systems to include universal and heavy forwarders, search heads, deployment server, and indexes
  • Design, develop, and implement new features for Splunk products
  • Provide training and support to IT staff on Splunk usage and best practices
  • Proven experience in designing, implementing, and maintaining Splunk solutions including, but not limited to: Splunk Enterprise, Splunk IT Service Intelligence, Splunk Log Management
  • Knowledge of Linux security best practices
  • Knowledge of cybersecurity compliance including RMF and IA standards
  • Excellent problem-solving and analytical skills
  • Service-oriented mindset
  • Strong communication and collaboration skills
  • At least one Splunk Certification: Splunk Certified for Splunk IT Service Intelligence (ITSI), Splunk Certified Administrator (SCA)

Nice To Haves

  • Experience integrating Splunk with ServiceNow to enable automated incident management, problem management, and change management workflows
  • Knowledge of security compliance and ATO (Authority to Operate) support
  • Preferred knowledge of FISMA (Federal Information Security Management Act) requirements
  • Current Security+ or DOD 8570 IAT Level II Certification
  • AWS or Azure Certification
  • ITIL v4 Certification
  • Strong understanding of IT operations, security, and business intelligence
  • Good team player with a strong willingness to help others
  • Experience scripting in the following preferred: Python, Perl, and JavaScript in relation to Splunk Apps/Add-ons, SQL for querying structured data, Knowledge of XML and JSON for data handling, Splunk Search Processing Language (SPL) for data analysis in Splunk

Responsibilities

  • Design core scripts to automate Splunk maintenance and alerting tasks
  • Develop dashboards and reports to display business-critical information
  • Develop and maintain dashboards, reports, and alerts to ensure efficient monitoring and management of IT systems
  • Engage with Product Owners to align platform capabilities with evolving business needs
  • Create scalable, flexible security architectures using standards-based integrations
  • Assist in developing policies for the secure operation of Splunk infrastructure
  • Support cloud-based deployment and sustainment (AWS and Azure)
  • Conduct software integration testing and cybersecurity compliance tasks
  • Automate processes and develop efficiencies alongside development and install teams
  • Maintain infrastructure for integration, cyber compliance, and network administration
  • Support both UNIX/Linux and Windows-based systems
  • Collaborate with IT teams to identify, troubleshoot, and resolve IT issues using Splunk
  • Document configurations, changes, and troubleshooting procedures.
  • Support new operational needs by integrating Splunk with other enterprise security services as required by government customers
  • Collaborate with government customers to understand their specific security service integration requirements
  • Develop and maintain integration scripts and configurations for various enterprise security services
  • Onboard new data sources into the Splunk environment, ensuring proper indexing, data normalization, and data quality
  • Develop and maintain scripts and configurations for onboarding new data sources
  • Ensure seamless data flow from new data sources into Splunk
  • Troubleshoot and resolve issues related to onboarding new data sources

Benefits

  • flexible time off
  • robust learning resources
  • competitive compensation
  • benefits and learning and development opportunities
  • comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service