Full-Time

Splunk SOAR Administrator

Posted on 9/8/2026

G2IT

G2IT

No salary listed

No H1B Sponsorship

Suitland-Silver Hill, MD, USA

In Person

Travel may be required between NMIC and other designated CONUS and OCONUS locations.

US Top Secret Clearance Required

Bachelor's, Master's

Category
Cybersecurity (1)
Required Skills
Incident Response
Machine Learning
Version Control
Splunk
Requirements
  • A Bachelor's degree in Computer Science, Information Technology, Information Assurance, or a related discipline with 8+ years of relevant experience, or a Master's degree with 6+ years of relevant experience. 15+ years of experience, including at least 10 years supporting LAN/WAN technologies, may be considered in lieu of a degree.
  • An active TS/SCI security clearance is required.
  • An active IAT Level III certification, such as CISSP, is required.
  • 8+ years of engineering experience supporting Computer Network Defense.
  • 6+ years of experience with Splunk, including Splunk Add-ons, Apps, Technology Add-ons, and Universal Forwarder.
  • Expert knowledge of Splunk, including Splunk Enterprise, Splunk Enterprise Security, and Splunk SOAR.
  • Significant experience with the System/Software Development Life Cycle.
  • Strong analytical and problem-solving skills.
  • Effective verbal and written communication skills.
Responsibilities
  • Design, deploy, and maintain EAC backend architecture.
  • Administer the SOAR platform, including configuration, asset integrations, and custom fields.
  • Design, develop, test, and maintain automated SOAR playbooks for alert triage, enrichment, and risk-based response.
  • Integrate SOAR with Splunk Enterprise Security, ticketing systems, and threat intelligence feeds.
  • Manage clustering, replication, indexing performance, and license usage.
  • Apply DISA STIGs, SRGs, and NAVINTEL Information Assurance baselines.
  • Maintain version control, approval workflows, and playbook governance.
  • Configure and maintain secure transmission of Audit.XML records to Intelligence Community partners through ITS and troubleshoot transmission failures.
  • Implement standard incident response workflows aligned with MITRE ATT&CK, NIST SP 800-61, and HGCC N62 Defensive Cyber Operations procedures.
  • Travel between the National Maritime Intelligence Center and other designated CONUS and OCONUS locations as required to support program requirements.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A