{"id":1948264,"url":"https://alion.io/job/saic-cybersecurity-specialist-splunk-engineer","title":"Cybersecurity Specialist Splunk Engineer","company":{"id":58788,"name":"SAIC","domain":"saic.com","url":"https://alion.io/company/saic","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":98000,"max_usd":202000,"period":"year","method":"global_role_seniority_cell","sample_n":1567},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Bash","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"ServiceNow","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-10-02T17:42:15Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-07T22:52:19Z","board_verified":true,"closed_at":null,"days_open":5,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":5},"description":"SAIC has an opening for a Cybersecurity Specialist, Splunk Engineer. For the right candidate, this position may be remote anywhere in the United States.\nThis position is responsible for duties around supporting the tools and technologies that are owned and operated by the Enterprise Security Operations Center. The Splunk Engineer will support other organizations within the company delivering solutions for data-driven challenges that enable the company.\nThe individual should be knowledgeable on a number of security technologies, have a solid understanding of information security and networking and experience interacting with customers. Will be able to engage on tasks independently, document and communicate work efforts and provide technical support.\nThe position will be responsible for maintaining and tuning the signatures, interfaces, and technical processes to ensure the tools are operational and meet the requirements of Enterprise Security Operations.\nJob Duties:\nAdminister, install, configure, and maintain Splunk (cloud and on prem) and other SIEM/log management tools.\nDevelop, audit, and optimize correlation rules; collaborate with ESOC to create new detections.\nBuild and maintain dashboards, reports, alerts, and visualizations.\nCreate and optimize SPL queries; manage knowledge objects (field extractions, tags, lookups, macros).\nOnboard and manage data sources (syslog, HEC, forwarders, APIs).\nManage deployment servers and forwarders.\nMaintain inputs, reporting, and alerting across Azure and AWS environments.\nWork at the system level to improve performance and propose platform enhancements.\nDevelop scripts and integrations with security tools (Python, Bash, PowerShell).\nWork with workflow automation tools to orchestrate processes with ServiceNow and other security/infrastructure platforms.\nUse regular expressions (regex) for parsing, extraction, and automation.\nDocument procedures for data ingestion and maintain access controls for compliance.\nCreate and implement configuration standards, policies, and procedures for improved operations.\nDevelop program metrics to measure monitoring effectiveness.\nResolve incidents and issues; integrate changes with established change management processes.\nTrain and mentor ESOC members on SIEM capabilities and best practices.\nInterface with analysts and business stakeholders to ensure tools, dashboards, and applications meet requirements.\nCommunicate effectively with teams and clients.\nWork across Linux and Windows platforms.\nApply an understanding of networking technologies, workflows, and IT reporting.\n Required Education and Experience:\nBachelor’s Degree and 5+ years cybersecurity operation related experience or software analyst/programming related experience, or master’s degree and 3+ years related experience. An additional 4 years of experience may be considered in lieu of a degree. \nDemonstrated experience administering and engineering Splunk.\nMust obtain the Splunk Core Certified Admin certification within the first 3 months of employment.\nMust obtain the Azure AZ-900: Microsoft Azure Fundamentals certification within 6 months of employment.\nMust obtain the AWS Cloud Practitioner certification within 9 months of employment.\nAvailability to work flexible hours and be available for on call during rotations.\nMust be a US Citizen.","description_format":"text","description_chars":3330,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Digital Government","Engineering Services"],"lifecycle":[{"event":"open","at":"2026-10-06T08:16:08Z"}],"visa":[],"liveness":{"score":88,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.877,"p_room":1,"age_days":4,"expected_fill_days":25,"reasons":["conf:2","velocity","win:early","comp:brand"],"computed_at":"2026-10-07T05:47:15Z"},"pay":null,"html_url":"https://alion.io/job/saic-cybersecurity-specialist-splunk-engineer","json_url":"https://alion.io/job/saic-cybersecurity-specialist-splunk-engineer.json","meta":{"generated_at":"2026-10-08T00:43:33Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1142,"day_limit":5000,"remaining_today":3858,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":58788},"rest":"https://alion.io/mcp/rest/get_company?id=58788"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fsaic-cybersecurity-specialist-splunk-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fsaic-cybersecurity-specialist-splunk-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fsaic-cybersecurity-specialist-splunk-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/saic-cybersecurity-specialist-splunk-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fsaic-cybersecurity-specialist-splunk-engineer"}]}