Splunk Cybersecurity SME (Remote)
Dragonfli GroupAbout the role
Description
Dragonfli Group is a cybersecurity and IT consulting firm based in Washington, DC, supporting clients across the federal and commercial sectors. We specialize in large-scale system integrations, cybersecurity architecture, and cloud engineering services.
We are seeking a Splunk Subject Matter Expert (SME) to support a large federal agency. The SME will lead the design, deployment, and maintenance of on-premises and cloud-based Splunk environments to support enterprise monitoring, alerting, and reporting.
This role requires deep expertise in Splunk system architecture, configuration, automation, and operational support across hybrid Unix/Linux and cloud environments. The SME will collaborate closely with DevOps, Security, and IT teams to ensure data integrity, optimal performance, and continuous system availability for mission-critical operations.
This is a contract-based position that may occasionally require off-hours or weekend support for upgrades and maintenance activities. This role requires US citizenship or permanent resident status.
Responsibilities:
- Architect, configure, and maintain large-scale Splunk Enterprise and Splunk Cloud environments.
- Manage and automate Splunk knowledge objects including fields, extractions, tags, lookups, event types, workflow actions, macros, and aliases across environments.
- Develop, tune, and optimize complex SPL (Search Processing Language) queries, dashboards, and alerts for operational visibility and reporting.
- Lead system upgrades, patching, and performance tuning across clustered Splunk infrastructures.
- Integrate Splunk with external systems and data sources using REST APIs, scripting, and automation frameworks.
- Design and develop automated workflows and dashboard interfaces to streamline system management.
- Collaborate with DevOps and Security teams to maintain secure, reliable, and compliant data pipelines.
- Document architecture, configurations, and procedures for continuous improvement and audit readiness.
- Provide mentorship to junior engineers and contribute to the knowledge base of the monitoring platform.
- Participate in after-hours maintenance windows and on-call support rotations as needed.
Requirements
Minimum Qualifications (Must-Have):
- 5+ years of direct experience with Splunk Enterprise or Splunk Cloud administration, deployment, and architecture.
- Strong understanding of knowledge object management (.conf and .cfg file structures) across recent Splunk versions.
- Proven ability to write, optimize, and debug SPL queries, dashboards, and alerts.
- Experience with Splunk deployment server, index clustering, and search head clustering.
- Hands-on experience with REST API integration between Splunk and external tools.
- Proficiency in scripting languages such as Python, Bash, PowerShell, JavaScript, and SQL for automation and integration.
- Experience with automation frameworks and CI/CD practices for configuration management.
- Excellent troubleshooting and performance tuning skills for large-scale environments.
- Strong communication and documentation skills with the ability to convey complex technical topics clearly.
- Must be a U.S. Citizen or Permanent Resident and reside within the continental United States.
Preferred Qualifications (Nice-to-Have):
- Experience leveraging the Splunk AI Assistant and other AI/ML tools to improve operational accuracy and efficiency.
- Advanced knowledge of Unix/Linux systems administration and troubleshooting.
- Familiarity with cloud integrations (AWS, Azure, or GCP) for Splunk hybrid deployments.
- Hands-on experience with the Splunk App for Data Science and Deep Learning (DSDL).
- Implementation and customization of Splunk SOAR (Security Orchestration, Automation, and Response) playbooks.
- Knowledge of NIST, FISMA, and FedRAMP frameworks and associated compliance controls.
- Strong understanding of network security architecture, logging standards, and defense-in-depth principles.
- Experience developing data ingestion pipelines and user onboarding automation for new Splunk projects.
- Background in cybersecurity, observability, or IT operations
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s