Jobs and Careers
DR

Splunk Cybersecurity SME (Remote)

Dragonfli Group
Washington, United StatesRemotefull_timeVerifiedPosted 29 Oct 2025

About the role

Description

Dragonfli Group is a cybersecurity and IT consulting firm based in Washington, DC, supporting clients across the federal and commercial sectors. We specialize in large-scale system integrations, cybersecurity architecture, and cloud engineering services.


We are seeking a Splunk Subject Matter Expert (SME) to support a large federal agency. The SME will lead the design, deployment, and maintenance of on-premises and cloud-based Splunk environments to support enterprise monitoring, alerting, and reporting.


This role requires deep expertise in Splunk system architecture, configuration, automation, and operational support across hybrid Unix/Linux and cloud environments. The SME will collaborate closely with DevOps, Security, and IT teams to ensure data integrity, optimal performance, and continuous system availability for mission-critical operations.


This is a contract-based position that may occasionally require off-hours or weekend support for upgrades and maintenance activities. This role requires US citizenship or permanent resident status.


Responsibilities:

  • Architect, configure, and maintain large-scale Splunk Enterprise and Splunk Cloud environments.
  • Manage and automate Splunk knowledge objects including fields, extractions, tags, lookups, event types, workflow actions, macros, and aliases across environments.
  • Develop, tune, and optimize complex SPL (Search Processing Language) queries, dashboards, and alerts for operational visibility and reporting.
  • Lead system upgrades, patching, and performance tuning across clustered Splunk infrastructures.
  • Integrate Splunk with external systems and data sources using REST APIs, scripting, and automation frameworks.
  • Design and develop automated workflows and dashboard interfaces to streamline system management.
  • Collaborate with DevOps and Security teams to maintain secure, reliable, and compliant data pipelines.
  • Document architecture, configurations, and procedures for continuous improvement and audit readiness.
  • Provide mentorship to junior engineers and contribute to the knowledge base of the monitoring platform.
  • Participate in after-hours maintenance windows and on-call support rotations as needed.

Requirements

Minimum Qualifications (Must-Have):

  • 5+ years of direct experience with Splunk Enterprise or Splunk Cloud administration, deployment, and architecture.
  • Strong understanding of knowledge object management (.conf and .cfg file structures) across recent Splunk versions.
  • Proven ability to write, optimize, and debug SPL queries, dashboards, and alerts.
  • Experience with Splunk deployment server, index clustering, and search head clustering.
  • Hands-on experience with REST API integration between Splunk and external tools.
  • Proficiency in scripting languages such as Python, Bash, PowerShell, JavaScript, and SQL for automation and integration.
  • Experience with automation frameworks and CI/CD practices for configuration management.
  • Excellent troubleshooting and performance tuning skills for large-scale environments.
  • Strong communication and documentation skills with the ability to convey complex technical topics clearly.
  • Must be a U.S. Citizen or Permanent Resident and reside within the continental United States.

Preferred Qualifications (Nice-to-Have):

  • Experience leveraging the Splunk AI Assistant and other AI/ML tools to improve operational accuracy and efficiency.
  • Advanced knowledge of Unix/Linux systems administration and troubleshooting.
  • Familiarity with cloud integrations (AWS, Azure, or GCP) for Splunk hybrid deployments.
  • Hands-on experience with the Splunk App for Data Science and Deep Learning (DSDL).
  • Implementation and customization of Splunk SOAR (Security Orchestration, Automation, and Response) playbooks.
  • Knowledge of NIST, FISMA, and FedRAMP frameworks and associated compliance controls.
  • Strong understanding of network security architecture, logging standards, and defense-in-depth principles.
  • Experience developing data ingestion pipelines and user onboarding automation for new Splunk projects.
  • Background in cybersecurity, observability, or IT operations

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Dragonfli Group

View company profile →