Job was saved successfully.
Job was removed from Saved Jobs.

Job Details


Senior Splunk Integrator



Full Time

On Site


Birmingham, Alabama, United States


Leidos is seeking a Senior Splunk Integrator to support our Air Force Intranet Control (AFINC) team at Maxwell Gunter AFB in Montgomery, AL. The AFINC Enterprise Network Analysis Team supports the 26 NOS, who requires services and solutions that accomplish and provide enabling capabilities to operate the DoDIN. These capabilities include, but are not limited to, Distributed Network Connectivity, Continuity of Operations, Information Management and Exchange, Standardization, Risk Management, DoD Enterprise Service Management Framework (DESMF), System Administration, Database Management, Account Management, Asset Management and Network Address Management.

Primary Responsibilities

  • Serve as Splunk engineer, senior leader and/or subject matter expert (SME) responsible for planning, designing, and implementing Splunk across multiple enterprise networks cluster implementations

  • Assesses current Splunk implementations for each network and recommend changes to distributed deployments to include Indexer Clustering, Search Head Clustering, Forwarders, daily indexing, search volume, number of data sources, number of users, custom apps/dashboards/visualizations

  • Monitor, troubleshoot, and analyze overall health of Splunk infrastructure

  • Perform root cause analysis, recommend, and implement tactical and strategic solutions to problems

  • Develop, update and document Splunk architecture, operational processes, and training materials

  • Ability to automate global, multi-site solutions with Ansible, Python, and Bash scripting techniques

  • Experience with various log ingestion methods, new data onboarding and related products, such as Log Agents, syslog, DB Connect (dbConnect), Universal Forwarder (UF) Agent, HTTP Event Collector

  • Working knowledge of Linux; general networking topics such as SSL, load balancing, routing protocols, firewall rules, and ability to support/interact with McAfee Endpoint Security System (ESS) for RHEL

  • Document steps required to design/engineer Splunk systems for each network to include virtual/real IP address, Fully Qualified Domain Name (FQDN), DNS entries, Role Based Access Controls (RBAC), service accounts, web certificates, licenses and physical/virtual location of each component

  • Candidate will oversee activities to include planning, researching, deploying, monitoring, upgrading, patching, and troubleshooting Splunk components spanning a large and complex environment

Basic Qualifications

  • BS degree and 8 – 12 years of prior relevant experience; additional direct related experience may be considered in lieu of a degree

  • Candidate must have a minimum of 10+ years of Splunk products experience and/or enterprise monitoring tools experience interacting with 3rd party systems preferably in role(s) such as a system administrator, engineer, developer or architect capacity

  • Splunk experience with design, implementation and administration in a large-scale environment preferably overseeing daily, weekly, monthly functions and best practices

  • Identify, analyze, define, & coordinate user, client, and stakeholder needs and translate them into technical requirements

  • Support day-to-day technical communication systems and incident tickets in support of operations

  • Candidate should have 4+ years of years of hands-on experience in:

    • System Integrator and/or administrator for Splunk users, searches/reports, dashboards, systems or 3rd party onboarding log data

    • Windows OS, UNIX or Linux-based systems support with experience in mid-to-large data center environments and patch/update management

    • Demonstrated advanced diagnostics, analytical, troubleshooting skills

  • Preferred system hardening experience

  • Strongly preferred Splunk Enterprise Security experience

  • Perform systems analysis, design review, integration of complex system applications

  • Experience with disaster recovery (DR) - expertise in risk reduction, hot/warm site DR architecture

  • Experience with physical servers and within virtualized environments such as VMware vSphere’s vCenter Server Appliance, ESXi hosts, virtual machines (VMs), SAN datastores, host bus adapters (HBA) fiber connectivity, and/or VM/Host distributed resource schedules (DRS) groups/rules

  • Scripting experience with regular expressions and languages such as: Ansible, Bash, JavaScript, HTML, Perl, PowerShell, or Python

  • CompTIA Security+ ce (continuing education) or (ISC)² CISSP

  • One Operating System Certification: CompTIA Linux+; Microsoft Technology Associate (MTA)

  • One Application Certification: Splunk Core Certified User; Splunk Core Certified Power User; Splunk Core Certified Advanced Power User; Splunk Enterprise Certified Admin; Splunk Enterprise Certified Architect; Splunk Certified Developer; Splunk Enterprise Security Certified Admin; Splunk IT Service Intelligence Certified Admin

  • Secret Clearance

Preferred Qualifications

  • CompTIA Linux+ or equivalent;

  • Splunk Core Certified Advanced Power User;

  • Splunk Enterprise Certified Admin or Splunk Enterprise Security Certified Admin;

  • Splunk Enterprise Certified Architect or Splunk Certified Developer;

Pay Range:

Pay Range $97,500.00 - $150,000.00 - $202,500.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.