Full-Time

Fedramp Software Engineer – Early Career

Posted on 3/6/2025

Splunk

Splunk

5,001-10,000 employees

Real-time machine data analytics for IT

Compensation Overview

$95.4k - $163.9k/yr

+ Incentive Compensation + Equity Awards + Long-term Cash Awards

No H1B Sponsorship

Colorado, USA

Candidates must be US citizens and must work on US soil.

Candidates must be US citizens and must work on US soil.

Candidates must be US citizens and must work on US soil.

US Citizenship Required

Category
Software Engineering (1)
Required Skills
Software Testing
Requirements
  • A Bachelors or Master's, in Computer Science, Software Engineering, Computer Engineering, Electrical Engineering, Mathematics or a related technical field.
  • This is a US-based position. US Citizenship is required and you must be working on US soil to be considered.
Responsibilities
  • Develop and deploy software to enhance the availability, performance, and reliability of Splunk’s Clustering service, while ensuring full compliance with FedRAMP.
  • Establish and maintain processes for continuous monitoring and auditing of systems to ensure compliance with FedRAMP controls.
  • Automate the deployment of our services in new provider regions, including FedRAMP environments.
  • Design, develop, code and test software systems, or applications for software improvements and new products over an extended period of time.
  • Build innovative solutions that enable rapid development, including non-functional aspects such as performance, security, globalization, and accessibility.
  • Make an impact through your recommended modifications to processes and procedures, and directly contribute to standard methodologies, architecture, and implementation.
  • Collaborate with colleagues from other teams for cross-functional collaboration, such as Security, Compliance, Support, and Education.
  • Interact with internal and external customers to identify issues and potential solutions.
  • Work on legacy implementations under the team's ownership.
  • Participate in the hiring and onboarding of incoming interns.
  • Participate in 24x7 on-call rotation.
Desired Qualifications
  • 2+ years of experience with one mainstream programming language, such as GoLang / Go or C++
  • Exposure to docker, Kubernetes, or public cloud platforms (e.g. AWS, GCP, Azure)
  • Demonstrated experience working with REST APIs
  • Experience working with relational or non-relational databases.
  • Experience with test-driven development, writing various levels of automated tests, such as unit test, functional test, integration test, system test, or performance / load test
  • Understanding of CI/CD
  • Familiarity with modern version control system, such as Git
  • Experience building meaningful software applications: in a class, as a personal hobby, as a job, as part of an open source project
  • Strong communication skills, verbal and written

Splunk analyzes large sets of machine data from IT systems, IoT devices, and security tools to provide real-time insights through its Data to Everything platform. It collects, searches, analyzes, and visualizes data so teams can monitor infrastructure, detect issues, and make informed decisions quickly. It differentiates itself by ingesting diverse data sources across IT, security, and business analytics, offering cross-domain visibility and security insights at scale, with integrations to technologies like Palo Alto Networks and Cisco. Its goal is to help organizations improve operational efficiency and security posture by turning data into actionable insights.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

San Francisco, California

Founded

2003

Simplify Jobs

Simplify's Take

What believers are saying

  • AI-powered data management and federated search reduce data silos and query latency.
  • Agent Builder and AI Canvas deepen daily usage across security and operations teams.
  • Cisco integration expands cross-sell into networking, observability, and digital resilience accounts.

What critics are saying

  • Cisco may prioritize broader platform bundling over Splunk-specific innovation.
  • Security vulnerabilities raise trust, patching costs, and buyer friction in regulated accounts.
  • Competitors offering cheaper in-place analytics pressure Splunk's ingest-led monetization model.

What makes Splunk unique

  • Unified security and observability platform spans Cisco networks, endpoints, cloud, and apps.
  • Real-time machine-data analytics powers SecOps, ITOps, engineering, and business workflows.
  • Enterprise-grade deployments support cloud, on-premises, and hybrid environments at scale.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Splunk who can refer or advise you

Benefits

Medical, dental and vision insurance plans for regular, full-time U.S. employees — choose the best plans for you and your family. Plus: Health Savings Account (HSA), Life insurance and survivor benefits, Flexible Spending Accounts (FSA), Business travel and accident insurance, Voluntary Critical Illness & Hospital Indemnity

Eligible employees enjoy: 401(k) Plan with a company match, Employee Stock Purchase Plan (ESPP), Equity awards, Bonus or commission program

We support you and your family: Paid parental leave, Mother rooms and wellness rooms, Family Planning

Your work/life balance is important to us, that's why we offer: 16 company holidays, 15 vacation days, 10 sick days, 10 bereavement days, 5 volunteer days

Ensuring our employees' success goes beyond insurance plans: Education reimbursement, Electric car charging stations, Employee Assistance Program (EAP), Stocked kitchens, Gym discounts/onsite fitness centers, Pet insurance discount, Student loan resources, Cool workspace with collaborative environments, 529 College Savings Plan

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
voco Hotels by IHG
Jun 9th, 2026
NetApp (NTAP): storage as strategic AI & security control plane.

NetApp (NTAP): storage as strategic AI & security control plane. 3h ago · 0:00 listen · Source: simplywall.st Summary. NetApp, Cisco, and Splunk have expanded their collaboration, launching new FlexPod AI solutions and a NetApp Splunk SOAR playbook. This initiative automates incident response at the storage layer to boost cyber resilience and AI deployment efficiency. What's interesting is this deep integration ties NetApp's core storage platform directly to customers' AI and ransomware defense workflows. This development highlights how NetApp is working to turn storage into a strategic AI and security control plane. The company reported US$6,925 million in revenue and US$1,276 million in net income for 2026. They are guiding fiscal 2027 revenue to between US$7,325 million and US$7,575 million, with operating margins projected at 22.1% to 23.1%. The bottom line is these new offerings could reshape NetApp's investment narrative by reinforcing demand for AI and cyber-resilient infrastructure. This is an AI-generated audio summary. Always check the original source for complete reporting.

Dr. Mercy Nwankwo
Apr 5th, 2026
OCSF explained: the shared data language security teams have been missing.

OCSF explained: the shared data language security teams have been missing. Welcome to the world of Open Cybersecurity Schema Framework (OCSF). Hey there, security enthusiasts! While the industry has been buzzing about models, copilots, and agents, there's a silent revolution happening beneath the surface. Vendors are now rallying around a shared language to describe security data, and leading this charge is the Open Cybersecurity Schema Framework (OCSF). OCSF offers a common ground for vendors, enterprises, and practitioners to represent security events, findings, objects, and context. This means less time spent on translating field names and parsers, and more time on actually analyzing and correlating data. In a world where security teams are juggling multiple sources of telemetry, OCSF is like a dream come true, offering a unified infrastructure that was once just a distant hope. Unlocking OCSF's potential. OCSF is an open-source framework designed for cybersecurity schemas, offering a vendor-neutral and format-agnostic approach. It provides application teams and data engineers with a shared structure for events, enabling analysts to work with a consistent language for threat detection and investigation. Now, let's dive into the real-world impact of OCSF within a security operations center (SOC). Imagine having to normalize data from various tools to correlate events and detect anomalies. OCSF simplifies this process by helping vendors align their schemas into a common model, streamlining data flow across different platforms without the need for extensive translations. The rise of OCSF. In the past two years, OCSF has gained significant momentum. Initially launched in August 2022 by Amazon AWS and Splunk, the project has garnered support from industry giants like Cloudflare, CrowdStrike, IBM, and many others. The community has rapidly expanded, with over 900 contributors now part of the OCSF ecosystem. OCSF: transforming the industry. Across the observability and security landscape, OCSF is making its mark. From AWS Security Lake to Splunk's data processing capabilities, OCSF is seamlessly integrated into various products and services. Palo Alto Networks, CrowdStrike, and other key players are leveraging OCSF to enhance data interoperability and streamline security operations. Embracing AI with OCSF. As AI technologies become more prevalent in cybersecurity, OCSF plays a crucial role in enabling teams to understand and analyze AI-generated telemetry. With OCSF's latest updates, security teams can better track AI-driven actions and identify potential security threats. Looking ahead with OCSF. Imagine a future where OCSF helps unravel complex AI interactions and safeguards sensitive data. With upcoming updates like OCSF 1.8.0, security teams can gain deeper insights into AI behaviors and mitigate risks more effectively. Join the OCSF revolution. As OCSF continues to evolve into a standard practice in the cybersecurity realm, it offers a unified framework that enhances data security and operational efficiency. In a world where data protection is paramount, OCSF serves as a vital tool for safeguarding sensitive information and combating evolving security threats.

Business Wire
Mar 31st, 2026
Resecurity launches native Splunk integration for real-time cyber threat intelligence

Resecurity, a cybersecurity and threat intelligence company, has launched a native integration with Splunk through a dedicated app on Splunkbase. The integration allows organisations to connect Resecurity's cyber threat intelligence with Splunk's ecosystem, enabling the ingestion of indicators of compromise and indicators of attack into Security Information and Event Management and Security Operations Center workflows. The app uses the TAXII protocol to facilitate threat intelligence feeds, allowing cybersecurity teams to correlate actionable intelligence with internal telemetry. Once ingested, the indexed data can enrich logs and accelerate visibility by providing additional context for analysis and investigation. Founded in 2016, Resecurity was recently named one of the top 10 fastest-growing private cybersecurity companies in Los Angeles by Inc. Magazine.

Carroll County News
Mar 31st, 2026
Resecurity introduces native integration with Splunk.

Resecurity introduces native integration with Splunk. * 3 hrs ago Resecurity (USA), a global cybersecurity and threat intelligence company trusted by Fortune 100 enterprises and government agencies, announced the implementation of a native integration with Splunk, delivered through a dedicated app published on Splunkbase. Resecurity introduces native integration with Splunk (SIEM). This seamless integration enables organizations of any size to connect Resecurity's cyber threat intelligence (CTI) with the Splunk global ecosystem, facilitating the timely ingestion of indicators of compromise (IOCs) and indicators of attack (IOA), along with ongoing enrichment of security events and logs within existing monitoring and investigation workflows. Through the Splunk app, cybersecurity teams can ingest threat intelligence feeds from Resecurity into Security Information and Event Management (SIEM) and Security Operations Center (SOC), using industry-standard mechanisms such as the TAXII protocol. This enables organizations to incorporate actionable intelligence from Resecurity and correlate it with internal telemetry. Once ingested, indexed threat intelligence data can be used to enrich logs and accelerate visibility by providing additional context for analysis, alerting, and investigation. The app is available via Splunkbase and can be deployed within Splunk Enterprise environments, allowing organizations to configure unparalleled ingestion and data analysis based on their operational requirements: Resecurity Threat Intelligence Resecurity continues to expand its integration ecosystem by supporting interoperability with widely adopted platforms and applications, enabling organizations to make effective use of threat intelligence in daily operations. About Resecurity Resecurity(R) is a cybersecurity company that delivers a unified endpoint protection, fraud prevention, risk management and cyber-threat intelligence platform. Known for providing best-of-breed, data-driven intelligence solutions, Resecurity's services and platforms focus on early-warning identification of data breaches and comprehensive protection against cybersecurity risks. Founded in 2016, it has been globally recognized as one of the world's most innovative cybersecurity companies with the mission of enabling organizations to combat cyber threats regardless of their sophistication. Most recently, by Inc. Magazine, Resecurity was named one of the Top 10 fastest-growing private cybersecurity companies in Los Angeles, California. Resecurity is a member of InfraGard National Members Alliance (INMA), AFCEA, NDIA, SIA, FS-ISAC and several American Chambers of Commerce worldwide. To learn more, visit https://resecurity.com.

Cisco
Mar 26th, 2026
Cisco at RSAC: building trust into agentic AI.

Cisco at RSAC: building trust into agentic AI. Agentic AI raises security questions, but agents can also be powerful allies. At RSAC, Cisco and Splunk show the way towards a trusted agentic future. Key takeaways. Summary is AI-generated, editor-reviewed. * Agentic AI's rapid evolution demands trust-building to harness its potential and mitigate security risks. * Cisco's solutions, like DefenseClaw and Zero Trust Access, aim to secure agentic environments. * Agentic SOCs empower security teams to predict and respond to threats at machine speed. "We're living in one of the most exciting and simultaneously the most disorienting times in human history," said Cisco's Jeetu Patel at RSAC 2026 in San Franciso this week. Given the lightning-fast changes driven by agentic AI, he wasn't exaggerating. Building trust into agentic AI is critical to lessening that disorientation - and unleashing the vast promise of AI. "The ability to delegate a task in a trusted form, versus just delegating a task, not being trusted, is going to be the difference between being a market leader versus being bankrupt," said Patel, who is Cisco's president and chief product officer. Cisco is taking on the challenge of ensuring that they are secure and trusted, especially as Linkom-PC approach a time when organizations will deploy thousands of agents, all acting independently. At RSA, the company announced essential solutions like extended Zero Trust Access for agents; DefenseClaw, an open-source secure agent framework; and AI Defense: Explorer Edition, which democratizes AI safety and security for builders. New innovations from Splunk, a Cisco company, include Exposure Analytics, Detection Studio, Federated Search, and agentic security operations center (SOC) expansions. Because as Patel stressed, "We need to fundamentally reimagine security for the agentic workforce." From a Cisco perspective that centers on three key strategies: protecting agents from the world; protecting the world from agents; and responding to threats at machine speed and scale. DefenseClaw: protecting agents from the world. To protect agents from being compromised, Cisco has implemented a variety of solutions - many open sourced. And since OpenClaw has made it easier and faster to develop and deploy agentic solutions, additional security is ever more imperative. "We've had a multitude of these tools," Patel said of open-source offerings from Cisco available free in AI Defense Explorer Edition. "Because what's really important is making sure that we work together as a community and provide tools and knowledge to each other. And so, we have this open-source community where all of these different tools - from a Skill Scanner to an AI Bill of Materials, to an MCP Scanner - all of these tools are available on GitHub." More on AI Defense: Explorer Edition from DJ Sampath, SVP and General Manager, Cisco AI Software and Platform Any of these will be activated by a new solution, DefenseClaw, a security framework for OpenClaw deployments. "If you're using OpenClaw and you want to make sure that you're safe and secure, DefenseClaw will help you do that," Patel added. "This also is completely open sourced." DefenseClaw is also designed to work with OpenShell, NVIDIA's container for OpenClaw deployments. "Every single time an agent executes with an OpenShell," Patel continued, "you're going to automatically activate these open-source services so that it can scan the skills and make sure that it's checking for vulnerabilities and scan the MCP servers... because we have to make sure that these agents are delegated work in a trusted manner." DJ Sampath, Cisco's SVP and general manager for AI software and platform, stressed that these solutions cover the full life cycle of AI projects, from pilot to production. "AI Defense Explorer Edition allows you to try all these fun things," he said. "And then when you upgrade that to the enterprise version of AI Defense, you seamlessly connect into Cisco Secure Access, into how you are pushing out these guardrails, how you do MCP scanning, all of that. That is the entire continuum of the lifecycle of understanding what AI attacks exist." Protecting the world from rogue agents: Zero Trust. In a seminar titled From Chatbots to Change Agents: Securing Agentic AI, Cisco's Matt Caulfield, VP of product management for identity, and Kevin Kennedy VP of product and solutions for security, laid out some of the key challenges - and solutions - around identity and access in vastly complicated agentic AI environments. One in which thousands of agents roam freely through internal data and SAAS applications - all with the agency to act independently. "When it comes to giving tools to agentic AI," Caulfield warned, "we are now opening up our organizations to a whole new level of security risk." So how do organizations protect against their own agents being compromised or from outside agents set loose by bad actors? Caulfield summed up three key steps. "Knowing your risk is first," he said. "If you don't have an agent-discovery tool, if you're not looking for agents in your environment, that's step number one. Second step is then controlling that access. So having a consistent place to do enforcement, investing in an AI gateway that can sit in between the agents and the resources, and supplying it with policy about what those agents are allowed to do and a life cycle for what they should do, and then prioritizing which tools you want to onboard. And then third, and most importantly, is agent governance and life cycle." Or as Kennedy summarized, "The key is know your agents, authorize every action, what they are allowed to do, what they are not allowed to do, and then adapt to risk because even actions that are allowed by policy are not necessarily safe." From a customer perspective, Jeremy Nelson, Insight's CISO for North America, weighed in on the importance of securing access, not just for humans, but for agents - along with his excitement around Cisco's extended Zero Trust solution. "Organizations are eager to embrace AI," he said, "but they need to do so without creating security coverage gaps. Cisco's Zero Trust Access for AI Agents gives visibility into agentic identities and restricts access to exactly what's needed. We're excited to bring these capabilities to customers to secure their data while scaling their AI initiatives." Peter Bailey, SVP and GM, Cisco Security business on the value of Cisco Zero Trust Securing the SOC at machine speed and scale. Of course, agents don't sleep and work faster and on a vastly larger scale than humans. So, when they fall into the wrong (human) hands they can be a formidable threat. The answer is defensive measures that never sleep, operate at massive scale, and act independently. John Morgan, SVP and general manager of Splunk Security, and Fred Frey, Splunk's director of software engineering, discussed how agentic AI is becoming a critical tool in the SOC. "The industry has been modernizing the security operations center for many years," Morgan said, "but it's still the case that threats are overwhelming our analysts. Now we have an obligation to stop analyst burnouts and stop threats from entering into our SOC. And we're going to think about doing this with AI and with agents. This is what we call the Agentic SOC." Frey emphasized that getting the Agentic SOC right is imperative, and he outlined key elements. "Agents out of the box is not what we need," Frey said. "We need agents to understand our business practices, our data, our query structure, the way we investigate alerts today. Agents can consume, retain, and recall massive amounts of data, and it's critical for them to surface them at just the right time. This builds trust; as it's learning our systems and our processes, we're building trust." Morgan believes that agentic systems, while not without risk, can be a game changer in empowering security teams - to enable an agentic future that's secure, trusted, and driving all-new efficiencies and innovations. "With the right trust and governance model," he concluded, "agentic systems can be powerful allies with us. An Agentic SOC provides certainty in a world that's full of non-predictability at this point. With threats running at machine speed, humans are going to need help. We need agents in our SOC, but this is not about replacing people. This is about empowerment. Empowering people to not just respond, but to predict and be proactive." John Morgan, SVP and GM, Splunk Security talks about how Cisco and Splunk work together to fortify the SOC

INACTIVE