Splunk SIEM Data Onboarding Engineer

Booz Allen Hamilton•Reston, VA
•Onsite

About The Position

The Splunk SIEM Data Onboarding Engineer is responsible for managing and enhancing our Splunk environment to ensure seamless data ingestion, analysis, and visualization. This role demands a deep understanding of Splunk architecture, data onboarding, and user management to support business needs and security operations.

Requirements

  • 2+ years of experience managing and configuring Splunk
  • 2+ years of experience in Splunk architecture, including indexers, search heads, forwarders, and deployment server
  • 2+ years of experience building pipelines to parse, normalize, enrich, mask or dedupe, and route data to Splunk
  • 2+ years of experience in Linux and Windows administration
  • Active TS/SCI clearance; willingness to take a polygraph exam
  • Associate’s degree and 5+ years of experience supporting IT projects and activities, Bachelor’s degree and 3+ years of experience supporting IT projects and activities, Master’s degree and 1+ years of experience supporting IT projects and activities, or 10+ years of experience supporting IT projects and activities in lieu of a degree
  • Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX, CCNP Security, CISA, CISSP, GCED, GCIH, or CCSP Certification, and a DoD 8570 Cyber Security Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date

Nice To Haves

  • 2+ years of experience with networking fundamentals, including TCP/UDP, TLS, syslog transport, firewall ports, and common transport issues
  • 2+ years of experience in basic troubleshooting with tools such as tcpdump or wireshark, basic vi/vim usage, setfacl, and SELinux
  • 1+ years of experience with STIGs or other organizational hardening standards working in regulated environments
  • 1+ years of experience with regex skills for field extraction and event breaking
  • Experience in SPL for validation, troubleshooting, and basic dashboards
  • Experience with scripting languages such as Python, Bash, or PowerShell
  • Experience with Cribl sources, destinations, routes, and collectors
  • Experience with Splunk REST API for automation and operational tasks
  • Knowledge of Git for code version control
  • Knowledge of Ansible playbooks

Responsibilities

  • Design, deploy, and manage Splunk infrastructure.
  • Develop and maintain Splunk dashboards, queries, and alerts.
  • Integrate Splunk with various data sources to ensure comprehensive data ingestion.
  • Monitor and troubleshoot Splunk performance issues.
  • Collaborate with cross-functional teams to gather requirements and provide Splunk solutions.
  • Implement and enforce best practices for Splunk data management and retention.
  • Provide user training and support for Splunk-related activities.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service