Frontend Splunk Security Engineer
PeratonAbout the role
Responsibilities
Peraton is seeking an experienced Splunk Front-End Engineer to design, build, and maintain rich, user-focused dashboards and reports. You’ll translate raw event data into actionable visualizations for asset managers, executives, and security operations teams. Prior FAA experience is highly desirable. Direct collaboration with FAA customers is expected. Remote position with occasional local on-site meeting support in the Washington, DC, Oklahoma City, OK or Egg Harbor Township, NJ area required. Candidates must be local to these areas.
KEY RESPONSIBILITIES• Architect and implement Splunk dashboards for data-center asset inventory and vulnerability reporting• Build Executive dashboards that filter and highlight critical assets for situational awareness• Normalize dashboard layouts, panels, and visualizations to a consistent styling and naming convention• Optimize searches and SPL queries for performance and scalability• Integrate new data sources and onboard security systems into Splunk• Map CVE and asset owner data into asset-centric dashboards• Produce and maintain dashboard documentation: data sources, queries, drill-downs, and user guides• Collaborate with stakeholders to plan new dashboards, define requirements, wireframes, and success metrics
- Assess, develop, and implement security policies and procedures to align with frameworks such as NIST RMF, FedRAMP, FISMA, ISO 27001, and DoD STIGs.
- Conduct security risk assessments and gap analyses to identify vulnerabilities in systems and networks.
- Ensure compliance with federal regulations, industry standards, and organizational security policies.
- Assist in the preparation of System Security Plans (SSPs), Security Control Assessments (SCAs), and Authority to Operate (ATO) packages.
- Perform Plan of Action & Milestones (POA&M) management, tracking remediation efforts for security findings.
- Monitor security logs, alerts, and events using SIEM tools (e.g., System Security / Information Assurance Analyst, ArcSight, etc.) to detect, investigate, and mitigate cyber threats.
- Respond to security incidents, vulnerabilities, and breaches, conducting forensic analysis and impact assessments.
- Develop and refine incident response plans (IRPs) and participate in cybersecurity exercises and drills.
- Configure and manage security controls, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint security, and encryption solutions.
- Support the implementation of Zero Trust Architecture (ZTA) and Identity & Access Management (IAM) controls.
- Perform patch management and vulnerability remediation for IT assets, ensuring compliance with security benchmarks (DISA STIGs, CIS Benchmarks, SCAP).
- Develop and maintain security documentation, policies, and procedures for system accreditation.
- Conduct security awareness training for employees and stakeholders.
- Support audit and certification processes, working with internal and external security assessors.
- Review secure software development lifecycle (SDLC) practices, ensuring applications meet security best practices.
- Assist in securing cloud-based environments (AWS, Azure, Google Cloud) through security controls like CASB, CSPM, and cloud encryption.
- Conduct security reviews for third-party applications and vendors to mitigate supply chain risks.
Qualifications
REQUIRED QUALIFICATIONS
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, Mathematics, Technology, or related IT field with 5 years of relevant experience; or Masters with 3 years of relevant experience; or High School with 9 years of relevant experience.
- Minimum 6 years hands-on experience building and supporting Splunk dashboards, reports, and saved searches.
- 3 years proficiency with SPL, Dashboard Studio, data models, and the Asset Framework.
- 3 years experience using the following tools and technologies: Splunk Enterprise (Search, SPL, Dashboard Studio, Data Models, Asset Framework), Splunk IT Service Intelligence (ITSI),Splunk Security Essential, JIRA, Git, REST APIs, JSON,Basic CSS/HTML for dashboard theming.
- US Citizenship required with the ability to obtain an FAA Public Trust clearance prior to start.PREFERRED QUALIFICATIONS
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, Mathematics, Technology, or related IT field with 6 years of relevant experience; or Masters with 4 years of relevant experience; or High School with 10 years of relevant experience
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Ethical Hac
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s