Take2 Consulting, LLC · 15 hours ago
Splunk Senior Engineer
Take2 Consulting, LLC is seeking a skilled Splunk Engineer to join their cybersecurity and IT operations team within a dynamic defense agency environment. The role involves managing Splunk deployments, optimizing UBA and SOAR functionalities, and providing leadership and mentorship to junior team members while ensuring compliance with security policies.
ConsultingLegalManagement Consulting
Responsibilities
Splunk Platform Management: Install, configure, and maintain Splunk Enterprise, UBA, and SOAR in both on-premises and cloud/hybrid architectures; perform system upgrades, patching, and troubleshooting. Strong preference for any Oracle cloud experience
UBA and SOAR Optimization: Customize and fine-tune UBA models for behavioral analytics; configure playbooks, integrations, and automated actions within SOAR to accelerate threat response. Coordinate directly with on-prem/cloud infrastructure teams to maintain and deploy these modules
Team Leadership & Mentoring: Supervise, mentor, and provide technical guidance to junior Splunk team members and peers; delegate tasks, review work quality, facilitate skills development, and foster a collaborative team environment in alignment with mission objectives
Security and Compliance: Implement and maintain Splunk best practices in accordance with defense agency security policies, compliance requirements, and data retention standards. Experience with STIGs mandatory
Incident Handling: Respond to incidents with appropriate logs and reports; proactively troubleshoot any log/analytic abnormalities preventatively
Collaboration & Agile Delivery: Work within Agile project teams, attending ceremonies (stand-ups, sprints, retrospectives) and using Jira for ticketing, backlog tracking, and documentation
Knowledge Sharing: Develop, update, and share technical documentation, standard operating procedures (SOPs), runbooks, and knowledge articles in alignment with agency practices. Work with many small, medium, and large teams to achieve agency and program objectives
Log Management and Analysis: Aggregate and parse logs from diverse data sources; develop and maintain dashboards, reports, alerts, and custom searches to surface actionable intelligence
Qualification
Required
At least 6 years of Splunk experience
Experience managing Splunk Enterprise, Splunk User Behavior Analytics (UBA), and Splunk Security Orchestration, Automation and Response (SOAR)
Practical, hands-on experience working within secure, compliance-driven environments
Experience with STIGs
Strong preference for any Oracle cloud experience
Experience using scripting (e.g., Python, Bash) for automation and data manipulation
Mastery in designing and tuning Splunk searches, dashboards, alerts, and CIM compliance
Experience with log sources common to defense/enterprise networks (Windows, Linux, network appliances, security devices)
Experience using Jira for workflow management and Agile methodologies for project delivery
Ability to manage a small team of technical professionals
Strong analytical and problem-solving skills
Skilled communicator, able to collaborate with IT, cybersecurity, and mission teams
Proactive learner—stays current on Splunk and security operations best practices
Preferred
Strong preference for experience briefing senior/executive leadership (both commercial and Federal)