Senior Splunk Engineer & Cyber Defense Analys
Job
Special Aerospace Security Services, Inc
Remote
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
76
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Job Title:
Senior Splunk Engineer /Cyber Defense Analyst Location:
Huntsville, AL (Redstone Arsenal Area) - 100%Onsite Clearance:
Active TS/SCI Eligible, SECRET requiredEmployment Type:
Full-Time Position Summary We are seeking an experienced Senior Splunk Engineer & Cyber Defense Analyst to lead SIEM engineering, detection content development, and proactive hunt operations for a major DoD program in Huntsville. This hybrid role combines deep Splunk engineering expertise with hands-on cyber threat hunting across classified environments. You will own the performance, scale, and security of a multi‑terabyte/day Splunk Enterprise ecosystem while driving hypothesis-based hunts and guiding analysts across the SOC. This position reports to both the SOC Manager and the Program ISSM. Core Responsibilities Splunk Platform Engineering (≈50%) Architect, deploy, and sustain clustered Splunk Enterprise 9.x+ environments (SHC, Indexer Clustering, Cluster Master) onRHEL 8/9
Engineer data ingestion pipelines Develop dashboards (Dashboard Studio), SPL searches, macros, and Python-based commands Threat Hunting & Detection Engineering (≈40%) Perform security monitoring procedures to identify, analyze and respond to cybersecurity events and incidents Conduct proactive hunts based onMITRE ATT&CK
across endpoint, network, and cloud telemetry Lead Risk-Based Alerting (RBA) and TI Framework development within Splunk ES Build and tune detections using SPL or Sigma Perform deep-dive incident investigations and supportJFHQ-DODIN
reporting Leadership & Mentorship (≈10%) Serve as the technical escalation point for the SOC Mentor Tier 4-8 analysts in SPL, detection engineering, and adversary TTPs Required Qualifications Active DoD TS/SCI (U.S. Citizenship required) 8+ years in Cyber/IT, including: - 5+ years Splunk Administration - 3+ years operational threat hunting Expert-level Splunk ES, CIM, btool, and search optimization experience Meets DoDM 8140.03 qualification for DCWF 511 or 531 (Intermediate+) Qualifying certifications: GCIA, GCIH, GCFA, GCDA, GNFA, or CySA+ Security+ CE (or equivalentIAT II/III
baseline requirement) Strong Python (Splunk SDK), Bash, and/or PowerShell scripting Highly Desired Skills Experience with Cribl Stream/Edge Advanced Splunk certifications (Architect, Consultant) Cloud telemetry integration experience (AWS GovCloud or Azure Gov IL5/IL6)Similar remote jobs
Genesis10
Columbus, OH
Posted2 days ago
Updated23 hours ago
WesBanco Bank Inc.
Columbus, OH
Posted2 days ago
Updated23 hours ago
University of Michigan Health System
Ann Arbor, MI
Posted2 days ago
Updated23 hours ago
Similar jobs in Redstone Arsenal, AL
National Aeronautics and Space Administration
Redstone Arsenal, AL
Posted2 days ago
Updated23 hours ago
Amentum
Redstone Arsenal, AL
Posted3 days ago
Updated1 day ago
HII Mission Technologies
Redstone Arsenal, AL
Posted3 days ago
Updated1 day ago
Similar jobs in Alabama
Prime HealthCare Staffing
Hueytown, AL
Posted2 days ago
Updated23 hours ago
Huntsville Utilities
Huntsville, AL
Posted2 days ago
Updated23 hours ago