- Home
- Jobs
- PACIFIC and INDOPACOM
- Splunk Enterprise Administrator (5552) (TS/SCI) (Ft. Meade, MD)

Splunk Enterprise Administrator (5552) (TS/SCI) (Ft. Meade, MD) at SMX
Fort Meade, MDFull-timePACIFIC and INDOPACOMPosted about 1 month ago
Apply with PipelineAbout the Role
<p>SMX is seeking a <strong>Splunk Enterprise Administrator</strong> who will be responsible for architecting, deploying, configuring, maintaining, and optimizing an enterprise-scale Splunk Enterprise and Splunk Enterprise Security (ES) environment. This role focuses on onboarding new data sources, optimizing search queries, building dashboards and reports, and maintaining the stability of the Splunk infrastructure. The Administrator ensures high availability, data integrity, and peak search performance across distributed Splunk topologies. The scope of this position includes an Army Intelligence security domain as defined by the Cybersecurity Director. Additionally, the Splunk Administrator is responsible for ensuring ICS 500-27 audit compliance and collaborating closely with cyber analysts and architects to implement data solutions that provide real-time visibility into critical systems and processes.</p>
<p><strong>This is a full-time onsite position in Ft. Meade, MD.</strong></p>
<p><strong>Essential Duties & Responsibilities</strong></p>
<ul>
<li>Splunk Infrastructure Management: Install, configure, upgrade, and administer multi-site distributed Splunk Enterprise topologies, including Indexer Clusters, Search Head Clusters (SHC), Deployment Servers, Heavy/Universal Forwarders (UF), and Technology Add-ons (TAs).</li>
<li>Enterprise Security (ES) Operations: Maintain Splunk ES frameworks, ensure Common Information Model (CIM) compliance, manage correlation searches, configure Risk-Based Alerting (RBA), and maintain threat intelligence feeds and lookup tables.</li>
<li>Linux System Administration: Perform OS-level configuration, storage provisioning, kernel tuning, and automation across underlying Red Hat Enterprise Linux (RHEL) / CentOS systems hosting Splunk components.</li>
<li>Advanced SPL Development: Design, optimize, and maintain complex Search Processing Language (SPL) queries, macros, and scheduled searches to minimize resource utilization and index scanning overhead.</li>
<li>Dashboards & Reporting: Build and customize operational dashboards, executive posture summaries, and tactical analytics views for SOC analysts, incident response teams, and leadership.</li>
<li>High Availability & Clustering: Maintain resilient multi-site indexer replication and search head clustering to prevent data loss and ensure uninterrupted operational visibility.</li>
<li>Disaster Recovery (DR): Develop, document, and regularly validate disaster recovery procedures, cold/warm backup pipelines, and rapid restoration protocols.</li>
<li>SLA & Ingest Monitoring: Establish automated health monitoring, alerting, and metric dashboards to identify data feed drop-offs, ingestion lag, forwarder heartbeat failures, and pipeline bottlenecks on high-impact systems.</li>
<li>STIG Implementation: Ensure rigorous Security Technical Implementation Guide (STIG) compliance and continuous vulnerability remediation across all Splunk software, apps, and host operating systems.</li>
<li>Architecture Documentation: Maintain comprehensive data flow diagrams, system architectural schematics, hardware/software baselines, standard operating procedures (SOPs), and log onboarding registries.</li>
<li>Troubleshooting and Performance Tuning:</li>
</ul>
<ul>
<li>
<ul>
<li>Monitor the health of the Splunk system, identify issues, and implement solutions to maintain high availability and performance.</li>
<li>Optimize queries, alerts, and settings to lower resource use and improve efficiency.</li>
<li>Resolve data ingestion and indexing issues.</li>
</ul>
</li>
</ul>
<p><strong>Required Skills, Experience & Education</strong></p>
<ul>
<li>Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work (and willingness for CI Poly).</li>
<li>Certifications:</li>
<ul>
<li>Splunk Enterprise Administrator</li>
<li>Security+ (or above)</li>
</ul>
<li>Education</li>
<ul>
<li>Bachelor’s degree in computer science, Information Technology, or a similar field OR Minimum of 5 years of experience working with Splunk, including installation, configuration, and management.</li>
</ul>
<li>Technical Skills</li>
<ul>
<li>3-5 years of hands-on experience installing, configuring, administering, and tuning distributed Splunk Enterprise and Splunk Enterprise Security environments.</li>
<li>Proficiency in managing Splunk components including forwarders, indexers, and search heads.</li>
<li>Strong understanding of SPL and the capacity to create custom dashboards and reports.</li>
<li>Experience in data parsing, field extraction, and indexing.</li>
</ul>
</ul>
<p><strong>Desired Skills/Experience</strong></p>
<ul>
<li>Experience transitioning a SIEM environment from Splunk to Elastic</li>
<li>Experience supporting Splunk Enterprise Security (ES).</li>
<li>Familiarity with scripting languages (e.g., Python, Bash) for automation.</li>
<li>Knowledge of security operations, including Splunk best practices.</li>
</ul>
<p> </p>
<p>Application Deadline: October 19, 2026</p>
<p>#CJPOST</p>
<p>#LI-onsite</p>
<p> </p><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p> </p>
<hr>
<p><span style="font-size: 16px;">The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.</span></p></div><div class="title">The proposed salary for this position is:</div><div class="pay-range"><span>$160,000</span><span class="divider">—</span><span>$190,000 USD</span></div></div></div><div class="content-conclusion"><p> </p>
<p>At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.</p>
<p>We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.</p>
<p>SMX is an Equal Opportunity employer including disabilities and veterans.</p>
<p><span data-teams="true"><span id="message-body-1758638857922" class="fui-ChatMyMessage__body rcngbzt ___eyw0iv0 f10pi13n ftqa4ok f2hkw1w f8hki3x f1d2448m f1bjia2o ffh67wi f1j6vpng f1pniga2 f987i1v f1ffjurs f15bsgw9 f14e48fq f18yb2kv fd6o370 ffwy5si f3znvyf f57olzd f4stah7 f480a47 fs1por5 fk6fouc figsok6 fkhj508 f19n0e5 f9ijwd5 fzqqayd f10ostut f1o0qvyv f9ggezi f1xp5gbu f150uoa4 ffyari3 fo7qwa0 f16xkysk fxowb0n f11ghf3q f13aoclr flypziy f10kwr27 fquw1qa fftr39l f13lathq f15hsm81 f2ss68y ffb60jq f8nuap2 f13nk4fk f7jacry fq08z5q fd9af6s fr74w9q fcl9uv6 f13sm7pj f1u6qqly f16wpxbl faim3u9 f6cs3qo fa2w2z3 fd39nx6 f10gn8j9 frcqmxy f1w9ws4k f1ddxkqj fd10euv fvuz61 f1nbc6gw"><span id="content-1758638857922" class="fui-Primitive ___16zla5h f1oy3dpc fqtknz5 fyvcxda"></span></span></span></p>
<div id="x_Signature"></div>
<p>Selected applicant may be subject to a background investigation and/or education verification.</p>
<p>SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).</p></div>
Related Roles
Identity Intelligence Analyst
SMX
Aiea, HICybersecurity SME Senior (5693) (TS/SCI) (Ft. Meade, MD)
SMX
Fort Meade, MDUnmanned Surface Vehicles (USV) Maintainer / Operator
SMX
JEB Little Creek, VAJICO Joint Interface Control Officer (5606) (TS/SCI) (Tampa, FL)
SMX
Tampa, FLSystems Administrator - Mid (5605) (TS/SCI) (Ft. Meade, MD)
SMX
Fort Meade, MDLogistics Analyst (5604) (TS/SCI) (Ft. Meade, MD)
SMX
Fort Meade, MD