Advanced Onion, Inc. · 11 hours ago
System Administrator - Splunk
ADVANCED ONION INC is seeking a skilled Splunk Administrator/Operator to join their cybersecurity and IT operations team within a defense agency environment. The role involves deploying, managing, and optimizing Splunk Enterprise and related tools to support mission-critical systems and cybersecurity goals.
Local BusinessSpace Travel
Responsibilities
Install, configure, and maintain Splunk Enterprise, UBA, and SOAR in both on-premises and cloud/hybrid architectures; perform system upgrades, patching, and troubleshooting
Customize and fine-tune UBA models for behavioral analytics; configure playbooks, integrations, and automated actions within SOAR to accelerate threat response
Implement and maintain Splunk best practices in accordance with defense agency security policies, compliance requirements, and data retention standards
Respond to incidents with appropriate logs and reports; proactively troubleshoot any log/analytic abnormalities preventatively
Work within Agile project teams, attending ceremonies (stand-ups, sprints, retrospectives) and using Jira for ticketing, backlog tracking, and documentation
Develop, update, and share technical documentation, standard operating procedures (SOPs), runbooks, and knowledge articles in alignment with agency practices
Aggregate and parse logs from diverse data sources; develop and maintain dashboards, reports, alerts, and custom searches to surface actionable intelligence
Qualification
Required
DoD 8570 IAT II (e.i. Security+), Splunk Certified Administrator or higher
4 years of relevant experience
Current Secret Clearance or higher
Proficient in deploying and managing Splunk Enterprise, UBA, SOAR, and other Splunk modules
Comfortable with scripting (e.g., Python, Bash) for automation and data manipulation
Experience in designing and tuning Splunk searches, dashboards, alerts, and CIM compliance
Familiarity with log sources common to defense/enterprise networks (Windows, Linux, network appliances, security devices)
Working knowledge of Jira for workflow management and Agile methodologies for project delivery
Must be able to work as a team member in a matrixed organization
Strong analytical and problem-solving skills; detail-oriented with a focus on operational excellence
Skilled communicator, able to collaborate with IT, cybersecurity, and mission teams in written and verbal communications with a positive attitude and customer-first approach
Proactive learner—stays current on Splunk and security operations best practices
Preferred
Strong preference for any Oracle cloud experience