Booz Allen Hamilton, Inc. logo

Splunk SIEM Data Onboarding Engineer

Job Overview

briefcase

Employment Type

Full-time
moneybag

Compensation

Salary
Range $99,000.00 - $225,000.00
clock

Work Schedule

Standard Hours
diamond

Benefits

Health Insurance
Life insurance
Disability insurance
financial benefits
Retirement benefits
paid leave
Professional Development

Job Description

Booz Allen Hamilton is a leading management and technology consulting firm known for delivering innovative solutions that drive tangible outcomes for both government and commercial clients. Established with a commitment to transforming the way organizations tackle complex challenges, Booz Allen leverages deep expertise in data analytics, cybersecurity, and digital transformation to empower clients worldwide. With a people-first culture that values collaboration, continuous learning, and ethical practice, Booz Allen Hamilton supports employees with extensive benefits, career growth opportunities, and a dynamic work environment. The company is renowned for its dedication to diversity, equity, and inclusion, and it fosters an environment where all employees can thrive and contribute meaningfully to impactful projects. Booz Allen's expansive presence across various sectors provides a broad range of collaborative and technological challenges, making it a vibrant workplace for professionals dedicated to innovation and excellence.

The Splunk SIEM Data Onboarding Engineer position at Booz Allen Hamilton is a critical role within the organization’s cybersecurity and data analytics practice. This role focuses on managing and enhancing the Splunk environment to support seamless data ingestion, analysis, and visualization – key components in detecting and responding to cybersecurity threats. The engineer will take ownership of the design, deployment, and management of Splunk infrastructure, ensuring high availability and optimal performance. Responsibilities extend to developing and maintaining complex Splunk dashboards, creating efficient queries, and configuring alerts that provide timely and actionable insights.

In addition to technical responsibilities, the role requires integration of Splunk with diverse data sources to enable comprehensive monitoring across security operations and business processes. The engineer will also be instrumental in troubleshooting performance issues, collaborating with cross-functional teams to tailor solutions that align with business needs, and enforcing best practices in data management and retention. Providing training and user support for Splunk-related activities forms an important part of the role, empowering teams across the business to leverage the platform effectively.

The position demands solid experience with Splunk architecture components such as indexers, search heads, forwarders, and deployment servers, alongside proficiency with Cribl for advanced data routing and enrichment workflows. Candidates must have strong Linux and Windows administration skills, scripting capabilities, and an understanding of REST APIs for automation. Security clearance (Active TS/SCI) and willingness to undergo a polygraph exam are mandatory, reflecting the sensitive nature of the work and client engagements.

Booz Allen emphasizes employee well-being with comprehensive benefits including health insurance, professional development, paid leave, and more. The compensation range for this role is competitive, between $99,000 and $225,000 annually, reflecting the expertise required and the strategic importance of the position. This role offers opportunity for candidates to work remotely, onsite, or in hybrid models depending on business needs, showcasing flexibility alongside a strong commitment to collaboration and communication. Overall, the Splunk SIEM Data Onboarding Engineer role at Booz Allen Hamilton offers a challenging yet rewarding career path for cybersecurity professionals focused on leveraging advanced analytics and security information event management tools to protect critical infrastructure and drive organizational success.

Job Requirements

  • 2+ years of experience managing and configuring Splunk and Cribl sources, destinations, routes, and collectors
  • 2+ years of experience in Splunk architecture including indexers, search heads, forwarders, and deployment servers
  • 2+ years of experience building pipelines to parse, normalize, enrich, mask or dedup, and route data to Splunk
  • 2+ years of experience authoring or maintaining props.conf, transforms.conf, inputs.conf, outputs.conf, and packaging apps or TAs
  • 2+ years of experience in Linux and Windows administration including file paths, services, permissions, and log locations
  • 1+ years of experience with Splunk REST API for automation and operational tasks
  • 1+ years of experience with Cribl Redmap or JavaScript functions
  • Active TS/SCI clearance
  • willingness to take a polygraph exam
  • Associate's degree and 5+ years of experience supporting IT projects and activities, Bachelor's degree and 3+ years of experience supporting IT projects and activities, Master's degree and 1+ years of experience supporting IT projects and activities, or 10+ years of experience supporting IT projects and activities in lieu of a degree
  • Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX, CCNP Security, CISA, CISSP, GCED, GCIH, or CCSP Certification, and a DoD 8570 Cyber Security Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date

Job Qualifications

  • Associate's degree and 5+ years of experience supporting IT projects and activities
  • Bachelor's degree and 3+ years of experience supporting IT projects and activities
  • Master's degree and 1+ years of experience supporting IT projects and activities
  • 10+ years of experience supporting IT projects and activities in lieu of a degree
  • Experience managing and configuring Splunk and Cribl sources, destinations, routes, and collectors
  • Experience in Splunk architecture including indexers, search heads, forwarders, and deployment servers
  • Experience building pipelines to parse, normalize, enrich, mask or dedup, and route data to Splunk
  • Experience authoring or maintaining props.conf, transforms.conf, inputs.conf, outputs.conf, and packaging apps or TAs
  • Experience in Linux and Windows administration including file paths, services, permissions, and log locations
  • Experience with Splunk REST API for automation and operational tasks
  • Experience with Cribl Redmap or JavaScript functions
  • Ability to obtain DoD 8570 IAT Level III Certification and a Cyber Security Service Provider - Infrastructure Support Certification within 30 days of start date
  • Active TS/SCI clearance with willingness to take a polygraph exam

Job Duties

  • Design, deploy, and manage Splunk infrastructure
  • Develop and maintain Splunk dashboards, queries, and alerts
  • Integrate Splunk with various data sources to ensure comprehensive data ingestion
  • Monitor and troubleshoot Splunk performance issues
  • Collaborate with cross-functional teams to gather requirements and provide Splunk solutions
  • Implement and enforce best practices for Splunk data management and retention
  • Provide user training and support for Splunk-related activities

Job Criteria

Experience

Mid Level (3-7 years)


Job Location

Your Profile Is Visible To Hiring Managers Across OysterLink.

We'll match you with best jobs

Get job offers faster

Business woman
Business man
Search For More Opportunities:

How Candidates Get Hired Faster

Apply to 2–3 similar roles

Complete profile & get best matches

Check new opportunities daily

Woman chef
Man chef