SIEM Administrator/Engineer
$80k - $120kSaic
Description SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency's security monitoring and analytics capabilities. This position will provide hands-on administration of the organization's existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security. The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment. ***This hybrid role requires a minimum of three on-site days per week in Washington, DC.*** Responsibilities Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security. Support the organization's transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases. Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs. Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS). Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search. Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable. Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting. Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity. Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities. Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions. Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes. Maintain technical documentation and take ownership of assigned technical issues and projects through resolution. Qualifications Requirements Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree) 5+ years experience relevant IT/cybersecurity experience. Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments. Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting. Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search. Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting. Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise. Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality. Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, TLS, and syslog. Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms. Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions. Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages. Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams. Preferred Qualifications Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash. Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages. Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration. Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments. Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK. Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies. Experience working in or closely supporting a Security Operations Center (SOC). Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications. Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors. #J-18808-Ljbffr Saic
$108k - $125k
Job DescriptionECS is seeking a Mid-level SIEM Engineer to work in our Washginton, DCoffice. ECS Federal is a leading information security... ...and SIEM (security incident and event monitoring) administration, deployment, and/or architectural design Certifications addressing...SuggestedLong term contractPermanent employmentFull timeImmediate start- SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and modernize monitoring and analytics capabilities. This role will provide hands-on administration of Splunk while helping transition security monitoring, log analytics, and...Suggested
- ...Job Description Job Description Senior Exchange Online (EXO) Administrator Washington, DC –100% onsite Per Federal contract U.S. citizenship is required Must be able to obtain Public Trust clearance Start Date- 08/2026 through 12/2027 with possibility of long...SuggestedLong term contractContract workWork at office
- ...candidate profiles across active roles and use resumes/profiles to understand which backgrounds may be a fit. THE ROLE As a Customer Engineer, Agent Builder - TO, you may work on projects that require strong execution, communication, analytical judgment, and the ability...Suggested
- Career Launch is hiring for a Customer Engineer, Agent Builder - TO in Washington, DC, to translate complex problems into clear actions. You will collaborate with product, operations, and customer-facing teams to drive critical initiatives and deliver measurable outcomes...Suggested
- A leading IT service provider in Washington, DC seeks an experienced Splunk Administrator. The role requires expertise in managing distributed Splunk installations, including event log management and custom app creation. The ideal candidate must have a strong background...
$107.9k - $195.05k
...national security against ever-adapting threats. Our division currently has an exciting opportunity for a Software Defined Radio (SDR) Engineer to perform design, development, and hardware/software integration in Arlington, VA for the Electronic Warfare Division.Our...Full time- ...position. Position Summary: ISI is seeking an experienced Engineering Technician to support multiple technical projects within a... ...candidate will have a strong background in construction administration, project management, and financial oversight. This role requires...Contract workFor contractorsWork at officeMonday to Friday
- ...solutions and an engaging culture. Description of Task to be Performed: AnaVation is seeking an experienced SIEM (Security Information and Event Management) Engineer to provide support to a mission critical customer. The selected candidate will be responsible for the...Temporary workImmediate startRemote work
- Leidos Inc in Arlington, VA is seeking an experienced SDR Engineer to design, develop, and integrate high-performance SDR systems using Ettus USRP hardware. You will build production-grade software close to the hardware, focusing on real-time RF signal processing and low...
- NCSL International is seeking an experienced SDR software engineer in Arlington, VA to design, develop, and deploy advanced SDR systems using Ettus USRP hardware. You will build high-performance C++ applications with UHD, implement real-time DSP, and optimize RF streaming...
- Incident Response Engineer-JourneymanIntermittent Telework: Arlington, VATS/SCI RequiredPay Range: $125K - $142KJob Description: The Incident... ...detection, triage, and validation of security events from SIEM, endpoint, network, and cloud security tools to distinguish true...Remote work
- ...detection signatures; deploy new detection signatures- Monitor SIEM events related to implemented IDS/IPS technologies- Configure and... ...required- BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline...
- ...TechnologyCGS is seeking a skilled CrowdStrike Engineer to provide subject matter expertise in... ...EDR/NGAV platforms and EOUSA SOC’s SIEM platform.Coordinate software updates with... ...:CrowdStrike Certified Falcon Administrator (CCFA) or platform equivalentCrowdStrike...Full timeFor contractorsWork at officeLocal areaFlexible hours
$148.5k - $223.9k
...the future of Salesforce.Overview:As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area, responsible... ..., including Security Information and Event Management (SIEM) systems for centralized log analysis and alerting, Endpoint Detection...Full time$154.05k - $278.48k
Leidos has an exciting opportunity for Cybersecurity Engineer SME in our Intel Security Sector's Analysis Solutions Business Area. Our talented... ...(security groups), endpoint protection tools (HBSS/Trellix), SIEM platforms (Splunk). Monitor system and network security using...Full timeImmediate startFlexible hours- ...Consultants (CTC) is seeking a Cybersecurity Engineer to support the Congressional Budget... ...platforms, and security tools, including SIEM, EDR/XDR, and cloud-native security... ...including encryption standards, secured administrative access, identity controls, network protections...Full timeContract workFor contractorsWork at officeLocal area
$112k - $179k
ResponsibilitiesPeraton is seeking to hire an experienced Cybersecurity Engineer for its Federal Strategic Cyber group. Location: Chandler, AZ or... ..., cloud, mobile, and hybrid environments.Integrate and optimize SIEM, SOAR, and NDR platforms to improve detection and response...Contract workShift work- DescriptionThis is a mid-level firewall engineer position within the Vanguard contract, providing... ..., Zenoss, NeuralStar or other similar SIEM monitoring tools.Required Clearance:US... ...Hat Linux/CentOS and Ubuntu including administration scripting is a plus.ITIL Foundation...Contract workWork at office
$220k - $240k
GovCIO is hiring a Cybersecurity Engineer (RMF / Zero Trust) with an active Secret clearance to design, implement, and maintain cybersecurity... ...-on experience with Security Information and Event Management (SIEM) toolsSkilled in conducting vulnerability scanning and...Remote work- ...Ho Chunk, Incorporated, is seeking an exceptional Cybersecurity Engineer to design, implement, and maintain enterprise security controls... ..., monitoring, and audit capabilities integrated with enterprise SIEM tools.Monitor, analyze, and respond to security events using SIEM...Permanent employmentFull timeContract workWork at officeLocal areaFlexible hours
$107.9k - $195.05k
...TS/SCI RequiredLeidos is hiring a Splunk SOAR Administrator to join our team in Suitland, MD. In this role, you will provide engineering, operations, and technical support for Security Information and Event Management (SIEM) platforms that support threat detection, compliance...Full timeWork at office- ...EngineeringThe Senior Information Security Engineer is a hands-on platform owner within the... ...teams.• Integrate platforms with SIEM and SOAR for enrichment, correlation, and... ...changeIdentify opportunities to improve clinical and administrative processesMake appropriate decisions,...Work experience placement2 days per week
$120k - $200k
...Forward Deployed Engineer Picogrid is a leading venture-backed defense technology company founded to bridge the decades-long gap between... ...(idam) providers, security information and event management (siem) systems, and cross domain solutions (cdss). Preferred Qualifications...Permanent employmentWork at officeRelocation package- We are seeking a Sales Engineer to partner with a Named Account Manager in a defined territory. This role is designed for a technically strong... ...articulate and design solutions across: SecOps modernization (SIEM, SOAR, XDR)Zero Trust and SASE architecturesCloud and hybrid...WorldwideHome office
$146k - $234k
...Mission supports the Federal Aviation Administration by delivering mission-critical Cyber professionals... ...team of experts provides innovative engineering, logistics, sustainment, and customer... ...operations including threat hunting, SIEM, and incident responseFamiliarity with...Contract workShift work$120k - $150k
...We have an immediate need for a Systems Engineer to provide onsite support at the Mark Center... ...with a team of high-performance system administrators and security professionals to deploy,... ...security information and event management (SIEM) systems.Capability to swiftly resolve...Work at officeImmediate startFlexible hours$99k - $225k
...careful planning. That’s why we need you, a seasoned network security engineer who knows how to develop the exact network the DoD needs. As a... ...dateNice If You Have: Experience integrating Illumio with SIEM, EDR, or vulnerability management platformsExperience with container...Full timeContract workPart timeWork at officeLocal areaRemote work$86.8k - $198k
...Job Number: R0246908 Cribl Engineer The Opportunity: We are seeking a talented and... ...strong focus on feeding our downstream SIEM ecosystem. Your primary focus will be designing... ...: Experience with Linux or Unix administration Experience writing complex Regular...Full timeContract workPart timeWork at officeLocal areaRemote work- ...reimbursementand more! We are seeking a SOAR Engineer for an opportunity that is 100% onsite... .... Integrate security tools such as SIEM, EDR, threat intelligence, ticketing, and... ...Playbook Development Cloud Security Linux Administration Git / CI-CD Security Tool Integrations...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SIEM Administrator/Engineer. Be the first to apply!
- residential administrator Washington DC
- admin data entry Washington DC
- department administrator Washington DC
- warranty administrator Washington DC
- jira administrator Washington DC
- encompass administrator Washington DC
- cybersecurity administrator Washington DC
- 401k administrator Washington DC
- junior sap basis administrator Washington DC
- clinic administrator Washington DC


