See all roles

Splunk Architect / Subject Matter Expert (SME)

Work from home Full-time role Hiring

ECS is seeking a Splunk Architect / Subject Matter Expert (SME) to work remotely. Please Note: This position is contingent upon contract award.

ECS Federal is seeking an experienced Splunk Architect to design, build, and optimize an integrated SplunkSOAR+UBA+Core environment with automated compliance via QmulosQ‑Compliance/Q‑Audit for a long‑term Federal program. You will lead hybrid (remote‑first) engineering efforts that advance the client toward OMBM‑21‑31 Event Logging Level3 while mapping evidence to NIST 800‑53, FISMA, and NERC CIP.

  • PositionResponsibilities:

    • Architect & Engineer Splunk Core, SOAR, and UBA tiers; develop data‑ingest blueprints and high‑level architecture.
    • Automate Compliance using Q‑Compliance/Q‑Audit to map controls and produce real‑time dashboards.
    • Develop SOAR Playbooks&UBA Models for privileged‑account misuse, lateral movement, and OT/IT segmentation alerts.
    • Integrate OT Log Sources via secure one‑way transfers and document risk mitigations.
    • Lead Workshops & KnowledgeTransfer sessions; create Section 508‑compliant diagrams and runbooks.
    • Mentor BPA analysts and junior engineers on Splunk best practices and compliance automation.

Salary Range: $150,000 - $190,000

General Description of Benefits

Qualifications
  • Hands‑on Experience
    • 3 + years architecting Splunk Enterprise / Splunk SOAR (Phantom) solutions in federal or critical‑infrastructure settings
    • 2 + years deploying Splunk UBA and Qmulos Q‑Compliance/Q‑Audit, including control mapping to NIST/FedRAMP
  • Proven ability to automate compliance evidence for OMB M‑21‑31, NIST RMF, and EO 14028 objectives.
  • Strong stakeholder‑engagement, documentation, and briefing skills suitable for C‑suite and COR audiences.
  • Clearance Requirement:

    • U.S. citizenship and eligibility to obtain a DOE public‑trust (Q level) clearance; sponsorship provided

  • Certifications/Licenses:

    • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related discipline (or equivalent experience).
    • Active Splunk certifications: Splunk Core Certified Admin and Splunk SOAR Certified Automation Developer
    • Preferred: Splunk Certified Architect, CISSP, CISM, or Qmulos Certified Professional.

Originally posted on Himalayas

Apply To this Job

You might like

Medical Scribe

Work from home Full-time role

Risk Partnerships Manager, Payment Networks

Work from home Full-time role

Director of Strategic Accounts

Work from home Full-time role

Principal Consultant, Field Services Management

Work from home Full-time role

PA Coordinator (11AM-8PM EST)

Work from home Full-time role

Customer Support Associate - Work from Home - Wilmington, NC

Work from home Full-time role

Staff Product Manager, SalesAI Forecasting

Work from home Full-time role

Pipefitter

Work from home Full-time role

Freelance Physics Expert - Quality Assurance (AI Trainer)

Work from home Full-time role

Senior Director, RWD Insights

Work from home Full-time role

Comcast Program Manager Co-op NJ - Mount Laurel, 1800 Bishops Gate

Work from home Full-time role

Experienced Pre-Licensed Customer Service Representative for Dynamic Insurance Support – Remote Work Opportunity with Comprehensive Training and Growth Prospects at arenaflex

Work from home Full-time role

Experienced Customer Service Representative for Remote Gig Staffing Support – Competitive Hourly Rate and Opportunity for Growth

Work from home Full-time role

Financial Clearance Representative Associate - Remote near Minneapolis, MN

Work from home Full-time role

Client Systems Engineer L5 [Remote]

Work from home Full-time role

Walmart Data Entry Job Part Time Remote - Hiring Now

Work from home Full-time role

Sr IT Technical Lead

Work from home Full-time role

Senior Partner Success Manager

Work from home Full-time role

Paralegal - Houston, TX Remote

Work from home Full-time role

FULL TIME Netflix Remote ( Chat Chat ) $75000/yearly ? US For

Work from home Full-time role