Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SIEM Administrator/Engineer

$80k - $120k

Saic

Description SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency's security monitoring and analytics capabilities. This position will provide hands-on administration of the organization's existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security. The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment. ***This hybrid role requires a minimum of three on-site days per week in Washington, DC.*** Responsibilities Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security. Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases. Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs. Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS). Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search. Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable. Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting. Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity. Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities. Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions. Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes. Maintain technical documentation and take ownership of assigned technical issues and projects through resolution. Qualifications Requirements Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree) 5+ years experience relevant IT/cybersecurity experience. Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments. Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting. Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search. Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting. Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise. Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality. Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, TLS, and syslog. Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms. Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions. Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages. Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams. Preferred Qualifications Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash. Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages. Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration. Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments. Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK. Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies. Experience working in or closely supporting a Security Operations Center (SOC). Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications. Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors. #J-18808-Ljbffr Saic

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the SIEM Administrator/Engineer in Washington DC vacancy
  • $108k - $125k

    Job DescriptionECS is seeking a Mid-level SIEM Engineer to work in our Washginton, DCoffice. ECS Federal is a leading information security...  ...and SIEM (security incident and event monitoring) administration, deployment, and/or architectural design Certifications addressing... 
    Suggested
    Long term contract
    Permanent employment
    Full time
    Immediate start

    ECS Federal

    Washington DC
    1 day ago
  • SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and modernize monitoring and analytics capabilities. This role will provide hands-on administration of Splunk while helping transition security monitoring, log analytics, and... 
    Suggested

    Saic

    Washington DC
    1 day ago
  •  ...Job Description Job Description Senior Exchange Online (EXO) Administrator Washington, DC –100% onsite Per Federal contract U.S. citizenship is required Must be able to obtain Public Trust clearance Start Date- 08/2026 through 12/2027 with possibility of long... 
    Suggested
    Long term contract
    Contract work
    Work at office

    System One

    Washington DC
    5 days ago
  •  ...candidate profiles across active roles and use resumes/profiles to understand which backgrounds may be a fit. THE ROLE As a Customer Engineer, Agent Builder - TO, you may work on projects that require strong execution, communication, analytical judgment, and the ability... 
    Suggested

    Career-Launch.net

    Washington DC
    1 day ago
  • Career Launch is hiring for a Customer Engineer, Agent Builder - TO in Washington, DC, to translate complex problems into clear actions. You will collaborate with product, operations, and customer-facing teams to drive critical initiatives and deliver measurable outcomes... 
    Suggested

    Career Launch

    Washington DC
    1 day ago
  • A leading IT service provider in Washington, DC seeks an experienced Splunk Administrator. The role requires expertise in managing distributed Splunk installations, including event log management and custom app creation. The ideal candidate must have a strong background... 

    Actionet Inc

    Washington DC
    1 day ago
  • $107.9k - $195.05k

     ...national security against ever-adapting threats. Our division currently has an exciting opportunity for a Software Defined Radio (SDR) Engineer to perform design, development, and hardware/software integration in Arlington, VA for the Electronic Warfare Division.Our... 
    Full time

    Leidos

    Arlington, VA
    4 days ago
  •  ...position. Position Summary: ISI is seeking an experienced Engineering Technician to support multiple technical projects within a...  ...candidate will have a strong background in construction administration, project management, and financial oversight. This role requires... 
    Contract work
    For contractors
    Work at office
    Monday to Friday

    ISI Professional Services

    Arlington, VA
    5 days ago
  •  ...solutions and an engaging culture.  Description of Task to be Performed: AnaVation is seeking an experienced SIEM (Security Information and Event Management) Engineer to provide support to a mission critical customer. The selected candidate will be responsible for the... 
    Temporary work
    Immediate start
    Remote work

    AnaVation

    Washington DC
    2 days ago
  • Leidos Inc in Arlington, VA is seeking an experienced SDR Engineer to design, develop, and integrate high-performance SDR systems using Ettus USRP hardware. You will build production-grade software close to the hardware, focusing on real-time RF signal processing and low... 

    Leidos Inc

    Arlington, VA
    2 days ago
  • NCSL International is seeking an experienced SDR software engineer in Arlington, VA to design, develop, and deploy advanced SDR systems using Ettus USRP hardware. You will build high-performance C++ applications with UHD, implement real-time DSP, and optimize RF streaming... 

    NCSL International

    Arlington, VA
    1 day ago
  • Incident Response Engineer-JourneymanIntermittent Telework: Arlington, VATS/SCI RequiredPay Range: $125K - $142KJob Description: The Incident...  ...detection, triage, and validation of security events from SIEM, endpoint, network, and cloud security tools to distinguish true... 
    Remote work

    Dunhill Professional Search

    Arlington, VA
    1 day ago
  •  ...detection signatures; deploy new detection signatures- Monitor SIEM events related to implemented IDS/IPS technologies- Configure and...  ...required- BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline... 

    NTT DATA

    Arlington, VA
    2 days ago
  •  ...TechnologyCGS is seeking a skilled CrowdStrike Engineer to provide subject matter expertise in...  ...EDR/NGAV platforms and EOUSA SOC’s SIEM platform.Coordinate software updates with...  ...:CrowdStrike Certified Falcon Administrator (CCFA) or platform equivalentCrowdStrike... 
    Full time
    For contractors
    Work at office
    Local area
    Flexible hours

    CONTACT GOVERNMENT SERVICES

    Washington DC
    4 days ago
  • $148.5k - $223.9k

     ...the future of Salesforce.Overview:As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area, responsible...  ..., including Security Information and Event Management (SIEM) systems for centralized log analysis and alerting, Endpoint Detection... 
    Full time

    Salesforce

    Washington DC
    22 hours ago
  • $154.05k - $278.48k

    Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector's Analysis Solutions Business Area. Our talented...  ...(security groups), endpoint protection tools (HBSS/Trellix), SIEM platforms (Splunk). Monitor system and network security using... 
    Full time
    Immediate start
    Flexible hours

    Leidos

    Bethesda, MD
    3 days ago
  •  ...Consultants (CTC) is seeking a Cybersecurity Engineer to support the Congressional Budget...  ...platforms, and security tools, including SIEM, EDR/XDR, and cloud-native security...  ...including encryption standards, secured administrative access, identity controls, network protections... 
    Full time
    Contract work
    For contractors
    Work at office
    Local area

    Computer Technologies Consultants (CTC)

    Washington DC
    4 days ago
  • $112k - $179k

    ResponsibilitiesPeraton is seeking to hire an experienced Cybersecurity Engineer for its Federal Strategic Cyber group. Location: Chandler, AZ or...  ..., cloud, mobile, and hybrid environments.Integrate and optimize SIEM, SOAR, and NDR platforms to improve detection and response... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  • DescriptionThis is a mid-level firewall engineer position within the Vanguard contract, providing...  ..., Zenoss, NeuralStar or other similar SIEM monitoring tools.Required Clearance:US...  ...Hat Linux/CentOS and Ubuntu including administration scripting is a plus.ITIL Foundation... 
    Contract work
    Work at office

    Science Applications International Corporation

    Beltsville, MD
    2 days ago
  • $220k - $240k

    GovCIO is hiring a Cybersecurity Engineer (RMF / Zero Trust) with an active Secret clearance to design, implement, and maintain cybersecurity...  ...-on experience with Security Information and Event Management (SIEM) toolsSkilled in conducting vulnerability scanning and... 
    Remote work

    Govcio

    Arlington, VA
    2 days ago
  •  ...Ho Chunk, Incorporated, is seeking an exceptional Cybersecurity Engineer to design, implement, and maintain enterprise security controls...  ..., monitoring, and audit capabilities integrated with enterprise SIEM tools.Monitor, analyze, and respond to security events using SIEM... 
    Permanent employment
    Full time
    Contract work
    Work at office
    Local area
    Flexible hours

    Ho Chunk

    Washington DC
    1 day ago
  • $107.9k - $195.05k

     ...TS/SCI RequiredLeidos is hiring a Splunk SOAR Administrator to join our team in Suitland, MD. In this role, you will provide engineering, operations, and technical support for Security Information and Event Management (SIEM) platforms that support threat detection, compliance... 
    Full time
    Work at office

    Leidos

    Suitland, MD
    1 day ago
  •  ...EngineeringThe Senior Information Security Engineer is a hands-on platform owner within the...  ...teams.• Integrate platforms with SIEM and SOAR for enrichment, correlation, and...  ...changeIdentify opportunities to improve clinical and administrative processesMake appropriate decisions,... 
    Work experience placement
    2 days per week

    Children's National Health System

    Silver Spring, MD
    22 hours ago
  • $120k - $200k

     ...Forward Deployed Engineer Picogrid is a leading venture-backed defense technology company founded to bridge the decades-long gap between...  ...(idam) providers, security information and event management (siem) systems, and cross domain solutions (cdss). Preferred Qualifications... 
    Permanent employment
    Work at office
    Relocation package

    Picogrid

    Washington DC
    1 day ago
  • We are seeking a Sales Engineer to partner with a Named Account Manager in a defined territory. This role is designed for a technically strong...  ...articulate and design solutions across: SecOps modernization (SIEM, SOAR, XDR)Zero Trust and SASE architecturesCloud and hybrid... 
    Worldwide
    Home office

    Fortinet

    Washington DC
    2 days ago
  • $146k - $234k

     ...Mission supports the Federal Aviation Administration by delivering mission-critical Cyber professionals...  ...team of experts provides innovative engineering, logistics, sustainment, and customer...  ...operations including threat hunting, SIEM, and incident responseFamiliarity with... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    4 days ago
  • $120k - $150k

     ...We have an immediate need for a Systems Engineer to provide onsite support at the Mark Center...  ...with a team of high-performance system administrators and security professionals to deploy,...  ...security information and event management (SIEM) systems.Capability to swiftly resolve... 
    Work at office
    Immediate start
    Flexible hours

    MCR

    Alexandria, VA
    22 hours ago
  • $99k - $225k

     ...careful planning. That’s why we need you, a seasoned network security engineer who knows how to develop the exact network the DoD needs. As a...  ...dateNice If You Have:   Experience integrating Illumio with SIEM, EDR, or vulnerability management platformsExperience with container... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    College Park, MD
    2 days ago
  • $86.8k - $198k

     ...Job Number: R0246908 Cribl Engineer The Opportunity: We are seeking a talented and...  ...strong focus on feeding our downstream SIEM ecosystem. Your primary focus will be designing...  ...: Experience with Linux or Unix administration Experience writing complex Regular... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Riverdale, MD
    1 day ago
  •  ...reimbursementand more! We are seeking a SOAR Engineer for an opportunity that is 100% onsite...  .... Integrate security tools such as SIEM, EDR, threat intelligence, ticketing, and...  ...Playbook Development Cloud Security Linux Administration Git / CI-CD Security Tool Integrations... 

    ClearFocus Technologies

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SIEM Administrator/Engineer. Be the first to apply!