AMERICAN SYSTEMS is seeking a professional with 8 – 10 years of experience and TS/SCI Clearance to be our next Senior Splunk Engineer at Malmstrom AFB, Montana.
Platform Engineering & Administration
- Install, configure, and maintain Splunk Enterprise and Splunk ES in classified, air-gapped, or cross-domain environments.
- Manage distributed architectures (indexers, search heads, cluster masters, deployment servers, forwarders) with a focus on reliability, performance, and security.
- Perform upgrades, patching, app deployment, performance tuning, and capacity planning.
- Implement and maintain backup/restore, DR procedures, and system hardening in accordance with DoD/IC and organizational policies.
Data Onboarding & Normalization
- Onboard logs from servers, network devices, security appliances, applications, and specialized classified systems.
- Develop and manage inputs, props, transforms, field extractions, and parsing to ensure high-quality, normalized data (CIM-compliant where applicable).
- Work with system owners and engineers to define logging requirements that support auditing, incident reconstruction, and compliance.
- Integrate Splunk with existing security tooling and infrastructure (e.g., host-based security, IDS/IPS, vulnerability scanners, identity systems).
Detection, Dashboards & Reporting
- Develop searches, correlation logic, alerts (where appropriate), and dashboards to surface security-relevant activity, system health, and compliance status.
- Create role-specific dashboards for cybersecurity staff, ISSOs/ISSMs, system administrators, and leadership.
- Support audit and inspection preparation (e.g., RMF, JSIG, NIST 800-53, CNSSI 1253) by building reports and evidence queries from Splunk.
- Implement and maintain data models, lookups, and other knowledge objects to support efficient analysis and reporting.
Security & Compliance Alignment
Ensure Splunk configurations and data flows comply with classified environment requirements, including handling caveats, data segregation, and need-to-know.
- Implement strict RBAC, data access controls, and logging of administrative actions.
- Support RMF and related processes by providing visibility into control effectiveness (e.g., AU-2, AU-6, AU-12, SI-4).
- Assist with continuous monitoring activities using Splunk as a key evidence and monitoring platform.
Collaboration & Technical Leadership (Non-SOC)
- Collaborate with cybersecurity engineers, ISSOs/ISSMs, system administrators, and network engineers to embed Splunk into system designs and modernization efforts.
- Provide expert guidance on how to leverage Splunk for troubleshooting, audit support, and security visibility.
- Mentor junior engineers and administrators on Splunk best practices, SPL queries, and platform usage.
- Contribute to Splunk standards, runbooks, and engineering documentation tailored for the classified environment.