Splunk Enterprise Administrator (5552) (TS/SCI) (Ft. Meade, MD)
- Onsite
- All operations jobs
About the role
SMX is seeking a Splunk Enterprise Administrator who will be responsible for architecting, deploying, configuring, maintaining, and optimizing an enterprise-scale Splunk Enterprise and Splunk Enterprise Security (ES) environment. This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the Splunk infrastructure. The Administrator ensures high availability, data integrity, and peak search performance across distributed Splunk topologies. The scope of this position includes an Army Intelligence security domain as defined by the Cybersecurity Director. Additionally, the Splunk Administrator is responsible for ensuring ICS 500-27 audit compliance and collaborating closely with cyber analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.
This is a full-time onsite position in Ft. Meade, MD.
Essential Duties & Responsibilities
- Splunk Infrastructure Management: Install, configure, upgrade, and administer multi-site distributed Splunk Enterprise topologies, including Indexer Clusters, Search Head Clusters (SHC), Deployment Servers, Heavy/Universal Forwarders (UF), and Technology Add-ons (TAs).
- Enterprise Security (ES) Operations: Maintain Splunk ES frameworks, ensure Common Information Model (CIM) compliance, manage correlation searches, configure Risk-Based Alerting (RBA), and maintain threat intelligence feeds and lookup tables.
- Linux System Administration: Perform OS-level configuration, storage provisioning, kernel tuning, and automation across underlying Red Hat Enterprise Linux (RHEL) / CentOS systems hosting Splunk components.
- Advanced SPL Development: Design, optimize, and maintain complex Search Processing Language (SPL) queries, macros, and scheduled searches to minimize resource utilization and index scanning overhead.
- Dashboards & Reporting: Build and customize operational dashboards, executive posture summaries, and tactical analytics views for SOC analysts, incident response teams, and leadership.
- High Availability & Clustering: Maintain resilient multi-site indexer replication and search head clustering to prevent data loss and ensure uninterrupted operational visibility.
- Disaster Recovery (DR): Develop, document, and regularly validate disaster recovery procedures, cold/warm backup pipelines, and rapid restoration protocols.
- SLA & Ingest Monitoring: Establish automated health monitoring, alerting, and metric dashboards to identify data feed drop-offs, ingestion lag, forwarder heartbeat failures, and pipeline bottlenecks on high-impact systems.
- STIG Implementation: Ensure rigorous Security Technical Implementation Guide (STIG) compliance and continuous vulnerability remediation across all Splunk software, apps, and host operating systems.
- Architecture Documentation: Maintain comprehensive data flow diagrams, system architectural schematics, hardware/software baselines, standard operating procedures (SOPs), and log onboarding registries.
- Troubleshooting and Performance Tuning:
-
- Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.
- Optimize queries, alerts, and settings to lower resource use and improve efficiency.
- Resolve data ingestion and indexing issues.
Required Skills, Experience & Education
- Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for CI Poly).
- Certifications:
- Splunk Enterprise Administrator
- Security+ (or above)
- Education
- Bachelor’s degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.
- Technical Skills
- 3-5 years of hands-on experience installing, configuring, administering, and tuning distributed Splunk Enterprise and Splunk Enterprise Security environments.
- Proficiency in managing Splunk components including forwarders, indexers, and search heads.
- Strong understanding of SPL and the capacity to create custom dashboards and reports.
- Experience in data parsing, field extraction, and indexing.
Desired Skills/Experience
- Experience transitioning a SIEM environment from Splunk to Elastic
- Experience supporting Splunk Enterprise Security (ES).
- Familiarity with scripting languages (e.g., Python, Bash) for automation.
- Knowledge of security operations, including Splunk best practices.
Application Deadline: October 19, 2026
#CJPOST
#LI-onsite
The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.
The proposed salary for this position is:$160,000—$190,000 USDAt SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.
We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.
SMX is an Equal Opportunity employer including disabilities and veterans.
Selected applicant may be subject to a background investigation and/or education verification.
SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
Description as published by SMX.