Leidos
Splunk Security Engineer
Suitland, MD
No sponsorship$108k-$195kDetected 1 hour ago
TypeScriptPythonSQLAWSAzureLinuxCybersecuritySIEMSOARDetection EngineeringIncident ResponseProcess ImprovementDNSFirewallCiscoWritingSharePointCISSP
About the role
- Are you ready to turn your skills into real-world impact?
- Analyze log events, correlate data across multiple sources, and enhance threat detection and response workflows.
- Connectors may use APIs, tokens, or service accounts, so understanding these options is important.
Responsibilities
- As a core member of our security engineering team, you will: Develop, maintain, and execute automated SOAR playbooks that interact across systems and devices.
- Configure and manage Splunk Enterprise Security, including maintaining CIM compliance, Risk-Based Alerting (RBA), ticketing, and SIEM integrations.
- Lead the full lifecycle of automation - from concept through deployment to documentation and tuning.
- Build visual dashboards, reports, and context-aware incident response tools.
- Support operational readiness, compliance, and proactive detection technologies across endpoint, cloud, network, and email infrastructures.
- Maintain existing/create new fleet of Development VMs (Windows, Linux) that allow you to test and demonstrate playbook functionality.
- Fully test and document playbook execution in the Development environment and be authoritative on presentation of playbook examples to new teams targeted for integration.
- Using SOAR connectors, design integrations between Splunk SOAR and standard DoD products such as Trellix ePO, Tanium, Cisco (FirePower, ISE, Email Gateways, AMP, switch/routers), Palo Alto Firewalls, Microsoft Active Directory, DNS, Exchange, SharePoint, IIS, SQL, Apache, Tomcat, RSA SecurID, Tenable.SC and Nessus, VMWare vCenter/ESXi, ServiceNow, Azure and AWS, NetApp, Windows and Linux.
Requirements
- Bachelor's degree and 8+ years of experience or Master's degree and 6+ years of experience.
- Additional experience, training, or certifications may be considered in lieu of a degree.
- Current IAT Level II certification (e.g., Security+ CE) or the ability to obtain within 30 days of Leidos start date.
- Current Splunk Certified Enterprise Security Administrator certification or the ability to obtain with 60 days of Leidos start date.
- Current Splunk SOAR Certified Automation Developer certification or the ability to obtain with 90 days of Leidos start date.
- Deep expertise in Splunk Administration, security event analysis, and Python-based automation.
- Strong working knowledge of cross-platform integrations and security tool APIs.
- Experience with process improvement in fast-moving security environments.
- What You'll Bring Required: Active TS/SCI clearance in DISS.
- Experience with Splunk SOAR/Phantom: playbook development, troubleshooting, and integrations.
Nice to have
- IAT Level III certification (e.g., CISSP).
- Technical writing skills for SOPs and integration documentation.
- Completion of Splunk SOAR training courses.
- Experience with MITRE ATT&CK integration and SOC-level triage workflows.
- Preferred: IAT Level III certification (e.g., CISSP).
Skills
- Your skills will directly strengthen national security operations.
- Get hands-on with advanced automation tools and frameworks.
Compensation
- Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary.
- Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026.
- Pay and Benefits Pay and benefits are fundamental to any career decision.
- That's why we craft compensation packages that reflect the importance of the work we do for our customers.
- Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.
Visa & Work Authorization
- fied applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregna
This listing is sourced directly from Leidos's careers page and normalized into a canonical job model.