Senior Splunk Integrator

06 Jun 2025

Vacancy expired!

Description Leidos is seeking a Senior Splunk Integrator to support our Air Force Intranet Control (AFINC) team at Maxwell Gunter AFB in Montgomery, AL.The AFINC Enterprise Network Analysis Team supports the 26 NOS, who requiresservices and solutions that accomplish and provide enabling capabilities to operate theDoDIN. These capabilities include, but are not limited to,Distributed Network Connectivity, Continuity of Operations, Information Management and Exchange, Standardization, Risk Management, DoD Enterprise Service Management Framework (DESMF), System Administration, Database Management, Account Management, Asset Managementand Network Address Management. Primary Responsibilities

Serve as Splunk engineer, senior leader and/or subject matter expert (SME) responsible for planning, designing, and implementing Splunk across multiple enterprise networks cluster implementations

Assesses current Splunk implementations for each network and recommend changes to distributed deployments to include Indexer Clustering, Search Head Clustering, Forwarders, daily indexing, search volume, number of data sources, number of users, custom apps/dashboards/visualizations

Monitor, troubleshoot, and analyze overall health of Splunk infrastructure

Perform root cause analysis, recommend, and implement tactical and strategic solutions to problems

Develop, update and document Splunk architecture, operational processes, and training materials

Ability to automate global, multi-site solutions with Ansible, Python, and Bash scripting techniques

Experience with various log ingestion methods, new data onboarding and related products, such as Log Agents, syslog, DB Connect (dbConnect), Universal Forwarder (UF) Agent, HTTP Event Collector

Working knowledge of Linux; general networking topics such as SSL, load balancing, routing protocols, firewall rules, and ability to support/interact with McAfee Endpoint Security System (ESS) for RHEL

Document steps required to design/engineer Splunk systems for each network to include virtual/real IP address, Fully Qualified Domain Name (FQDN), DNS entries, Role Based Access Controls (RBAC), service accounts, web certificates, licenses and physical/virtual location of each component

Candidate will oversee activities to include planning, researching, deploying, monitoring, upgrading, patching, and troubleshooting Splunk components spanning a large and complex environment

Basic Qualifications

BS degree and 8 – 12 years of prior relevant experience; additional direct related experience may be considered in lieu of a degree

Candidate must have a minimum of 10+ years of Splunk products experience and/or enterprise monitoring tools experience interacting with 3rdparty systems preferably in role(s) such as a system administrator, engineer, developer or architect capacity

Splunk experience with design, implementation and administration in a large-scale environment preferably overseeing daily, weekly, monthly functions and best practices

Identify, analyze, define, & coordinate user, client, and stakeholder needs and translate them into technical requirements

Support day-to-day technical communication systems and incident tickets in support of operations

Candidate should have 4+ years of years of hands-on experience in:

System Integrator and/or administrator for Splunk users, searches/reports, dashboards, systems or 3rdparty onboarding log data

Windows OS, UNIX or Linux-based systems support with experience in mid-to-large data center environments and patch/update management

Demonstrated advanced diagnostics, analytical, troubleshooting skills

Preferred system hardening experience

Strongly preferred Splunk Enterprise Security experience

Perform systems analysis, design review, integration of complex system applications

Experience with disaster recovery (DR) - expertise in risk reduction, hot/warm site DR architecture

Experience with physical servers and within virtualized environments such asVMwarevSphere’s vCenter Server Appliance, ESXi hosts, virtual machines (VMs), SAN datastores, host bus adapters (HBA) fiber connectivity, and/or VM/Host distributed resource schedules (DRS) groups/rules

Scripting experience with regular expressions and languages such as:Ansible, Bash, JavaScript, HTML, Perl,PowerShell, orPython

CompTIASecurity+ce (continuing education) or(ISC)CISSP

One Operating System Certification: CompTIALinux+; Microsoft Technology Associate (MTA)

One Application Certification: Splunk Core CertifiedUser; Splunk Core CertifiedPower User; Splunk Core CertifiedAdvanced Power User; Splunk Enterprise CertifiedAdmin; Splunk Enterprise CertifiedArchitect; Splunk CertifiedDeveloper; Splunk EnterpriseSecurity Certified Admin; SplunkIT Service IntelligenceCertified Admin

Secret Clearance

Preferred Qualifications

CompTIALinux+or equivalent;

Splunk Core CertifiedAdvanced Power User;

Splunk Enterprise CertifiedAdminor Splunk EnterpriseSecurity Certified Admin;

Splunk Enterprise CertifiedArchitector Splunk CertifiedDeveloper;

Pay Range:Pay Range $97,500.00 - $150,000.00 - $202,500.00The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. REQNUMBER: R-00112614All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.

Full-time
  • ID: #50051269
  • State: Alabama Mafbgunannx 00000 Mafbgunannx USA
  • City: Mafbgunannx
  • Salary: USD TBD TBD
  • Showed: 2023-06-06
  • Deadline: 2023-08-06
  • Category: Et cetera