Demo

Splunk Administrator

Cherokee Federal
Alexandria, VA Full Time
POSTED ON 1/28/2026 CLOSED ON 2/26/2026

What are the responsibilities and job description for the Splunk Administrator position at Cherokee Federal?

Job Description

Splunk SOAR Engineer

This position requires an active Public Trust clearance to be considered.

A government contract requires that this position be restricted to U.S. citizens or legal permanent residents.You must provide documentation that you are a U.S. citizen or legal permanent resident to qualify.

We are seeking a Splunk SOAR Engineer to design, build, and operate Splunk Phantom/SOAR automations that accelerate detection and response across hybrid environments, with a strong emphasis on AWS. This role integrates Splunk ES notable events with automated playbooks for triage, enrichment, containment, and ServiceNow Incident Response. The engineer will enforce safe automation through RBAC, approvals, confidence thresholds, secrets management, rollback paths, and audit-ready evidence, aligning operations with FISMA/NIST RMF, FedRAMP, and CMMC requirements.

Compensation & Benefits

Estimated Starting Salary Range for Splunk SOAR Engineer: $145K – $150K

Pay commensurate with experience.

Full time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided.Benefits are subject to change with or without notice.

Splunk SOAR Engineer Responsibilities Include

  • Design, develop, deploy, and maintain Splunk SOAR (Phantom) playbooks, apps, and integrations with secure, scalable configurations.
  • Integrate Splunk ES correlation searches and notable events into automated triage, enrichment, containment, and ServiceNow IR workflows using CIM-compliant data pipelines.
  • Build AWS-focused automations leveraging GuardDuty, CloudTrail, Security Hub, VPC Flow Logs, IAM, EC2, S3, and asset tagging for enrichment and response.
  • Implement response actions such as EC2 isolation, S3 access controls, EBS snapshots for forensics, IAM key rotation or revocation, MFA enforcement, and Security Hub updates, with human-in-the-loop approvals and rollback procedures.
  • Orchestrate endpoint and identity response by integrating EDR tools for host containment, IOC blocking, and remote response actions.
  • Integrate ServiceNow IR to auto-create and manage incidents, enrich tickets with cloud and CI context, track SLAs, manage approvals, and attach playbook evidence.
  • Optimize SOAR operations by tuning triggers, deduplicating events, reducing latency, standardizing reusable Python modules, and maintaining version control and documentation.
  • Collaborate with SOC, IR, and cloud teams to translate runbooks (e.g., phishing, malware, IAM abuse, EC2 compromise) into reliable, measurable automations.
  • Measure and report automation outcomes including MTTR reduction, auto-resolution rates, and SLA performance; support audits with control mapping and POA&M updates.
  • Maintain governance through RBAC, secrets handling, logging, change control, and safe-response guardrails.
  • Performs other job-related duties as assigned

Splunk SOAR Engineer Experience, Education, Skills, Abilities Requested

  • 5 years in SOC/IR or security engineering, including 3 years with Splunk SOAR (Phantom) and Splunk ES.
  • Hands-on AWS automation experience (GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs).
  • Proven ServiceNow Incident Response integration experience.
  • Experience integrating EDR APIs and chaining endpoint, identity, and cloud actions.
  • Proficiency in Python, AWS Boto3, Splunk/Phantom SDKs, and REST APIs.
  • Strong knowledge of MITRE ATT&CK, CVE/CVSS, CISA KEV, and risk-based automation.
  • Experience aligning operations with FISMA/NIST RMF, FedRAMP, and CMMC.
  • Relevant certifications (Splunk, AWS, Security , CySA , CISSP, GCDA/GCSA) preferred.
  • Experience with AWS Organizations, cross-account automation, and multi-region playbooks preferred.
  • Knowledge of ServiceNow flows, IR customization, and change management integrations preferred.
  • Must pass pre-employment qualifications of Cherokee Federal

Company Information

Criterion is a part of Cherokee Federal – the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

#CherokeeFederal

Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

Similar Searchable Job Titles

  • Security Automation Engineer
  • SOAR Engineer
  • Cloud Security Automation Engineer
  • SOC Automation Engineer
  • Security Orchestration Engineer

Keywords

  • Splunk SOAR
  • AWS Security
  • Incident Response
  • ServiceNow IR
  • Security Automation

Legal Disclaimer: All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.

Many of our job openings require access to government buildings or military installations.

Salary : $145,000 - $150,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Splunk Administrator?

Sign up to receive alerts about other jobs on the Splunk Administrator career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$83,502 - $107,152
Income Estimation: 
$104,896 - $133,785
Income Estimation: 
$123,198 - $153,566
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
This job has expired.
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cherokee Federal

  • Cherokee Federal Honolulu, HI
  • Job Description Information Systems Security Manager This position requires an active Secret clearance to be considered. A government contract requires tha... more
  • 4 Months Ago

  • Cherokee Federal Washington, DC
  • Job Description Human Resources Administrative Assistant Support As required by our governmental client, this position requires an active Secret clearance ... more
  • 4 Months Ago

  • Cherokee Federal George, MD
  • Job Description Cyber Analyst - Senior ***This position requires an active TS/Sensitive Compartmental Information (SCI) security clearance with the ability... more
  • 4 Months Ago

  • Cherokee Federal Frederick, MD
  • Job Description Functional AnalystAs required by our governmental client, this position requires being a US Citizen AND an active Secret clearance or the a... more
  • 4 Months Ago


Not the job you're looking for? Here are some other Splunk Administrator jobs in the Alexandria, VA area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!