Lead Splunk Engineer



Apply for this Job

Alexandria VA US



Job Requisition:

Lead Splunk Engineer

Job Description:

Are you someone concerned with the security of our nation?  Are you driven to protect and serve?  Are you skilled in cyber defense?  Then Leidos is the place for you.  We are ensuring our nation’s security in a partnership with the Customs and Border Protection Agency (a division of the Department of Homeland Security).  Our partnership focuses on the CBP Security Operations Center (SOC) where we provide around the clock cyber support focusing on some our nation’s toughest threats. 

Leidos currently has a need for a Lead Senior Splunk Engineer/SME for this highly visible cyber security program supporting Customs and Border Protection (CBP) security operations center (SOC).

The Lead Senior Splunk Engineer/SME will support the full system engineering life-cycle, including requirements analysis, design, development, implementation, integration, test, and documentation.  The Senior Splunk Engineer will follow defined best practices and operational workflows.


The Splunk SME will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security premium app, spanning security, performance, and operational roles.

The candidate should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.

The Splunk engineer will lead the Enterprise Splunk team, Cybersecurity Engineering team members and will be required to interact with end users to gather requirements, perform troubleshooting and provide assistance with the creation of Splunk search queries and dashboards. The Splunk engineer will be required interact with senior management, as necessary.


Masters with 15 – 20 years of prior relevant experience or Doctorate with 13 – 16 years of prior relevant experience.

In addition:

4+ years of experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environment

3+ Years of experience in Linux and SQL/ODBC interfaces

2+ Years of experience in app interface development, using REST APIs

Previous project management experience.

Ability to follow Change & Configuration Management

Strong problem solving abilities with an analytic and qualitative eye for reasoning under pressure

Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision

Knowledge of Cloud Services such as AWS, Azure, Office365

Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell

Splunk Certified Architect Certification

Splunk Certified Administrator Certification

Must have an active Secret Clearance and in addition, must have a current or be able to favorably pass a 5 year (BI) Background Investigation to join this program.


– Previous experience supporting DHS Programs 

– Experience in SQL

– Current or former completed Splunk training

– Prior experience a in Splunk professional services role

– Experience in automating Splunk Deployments and orchestration with in a Cloud environment

– Redhat Certification

External Referral Bonus:


Potential for Telework:


Clearance Level Required:




Scheduled Weekly Hours:




Requisition Category:


Job Family:

Cyber Security



Apply for this Job


JBLeidos / An Equal Opportunity Employer