Science Applications International Corp logo

SIEM Administrator/Engineer

Science Applications International Corp
  • Washington, DC
  • $80,001–$120,000 Per Year
2 days ago
Science Applications International Corp

Job Description

SIEM Administrator/Engineer

Job ID: 2616042

Location: Washington, DC, United States

Date Posted: Aug 25, 2026

Category: Cyber

Subcategory: Cybersecurity Spec

Schedule: Full-Time

Shift: Day Job

Travel: No

Minimum Clearance Required: None

Clearance Level Must Be Able to Obtain: Public Trust

Potential for Remote Work: Hybrid

Benefits: Click here

Share: mail

Apply Now >

Apply Now >

Job Description

Description

SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity operations and the modernization of the agency''s security monitoring and analytics capabilities. This position will provide hands-on administration of the organization''s existing Splunk environment while helping transition security monitoring, log analytics, and detection capabilities to Elastic / Elastic Security.

The ideal candidate has strong hands-on SIEM administration experience and is ready to grow into a broader engineering role. The successful candidate should be able to independently administer and troubleshoot production SIEM and logging infrastructure while demonstrating the technical curiosity, critical thinking, ownership, and initiative necessary to solve problems and improve the environment.

  • This hybrid role requires a minimum of three on-site days per week in Washington, DC.*

Responsibilities

  • Administer, maintain, monitor, and troubleshoot the existing Splunk Enterprise / Splunk ES environment while supporting the implementation and operationalization of Elastic / Elastic Security.
  • Support the organization''s transition from Splunk to Elastic, including migration and validation of data sources, searches, dashboards, reports, alerts, and security use cases.
  • Configure, manage, and troubleshoot enterprise log ingestion pipelines, including syslog, Windows Event Collection/Forwarding, Splunk forwarders, Elastic agents, network and security devices, applications, databases, cloud services, and APIs.
  • Onboard new data sources and ensure telemetry is reliably collected, parsed, normalized, enriched, indexed, and searchable using applicable standards such as Splunk CIM and Elastic Common Schema (ECS).
  • Troubleshoot logging and telemetry issues across the complete data path, from the originating system through collection, transport, ingestion, indexing, and search.
  • Develop, maintain, and optimize SIEM searches, dashboards, reports, alerts, and security detections using SPL and Elastic query technologies, including KQL, ES|QL, EQL, and Query DSL as applicable.
  • Use SQL and other query languages to analyze data, validate results, troubleshoot integrations, and support cybersecurity investigations and reporting.
  • Monitor and optimize SIEM platform health, performance, storage, ingestion, retention, and capacity.
  • Work with security analysts and cybersecurity engineers to develop, test, tune, and improve security monitoring and detection capabilities.
  • Investigate technical problems, test hypotheses, identify root causes, and implement or recommend practical solutions.
  • Use scripting, APIs, and automation where appropriate to improve SIEM administration, monitoring, data onboarding, and repetitive operational processes.
  • Maintain technical documentation and take ownership of assigned technical issues and projects through resolution.

Qualifications

Requirements

  • Bachelor''s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree)

  • 5+ years experience relevant IT/cybersecurity experience.

  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card

  • 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments.

  • Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting.

  • Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search.

  • Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting.

  • Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise.

  • Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality.

  • Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, HTTP/HTTPS, TLS, and syslog.

  • Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms.

  • Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions.

  • Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages.

  • Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams.

Preferred Qualifications

  • Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash.

  • Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages.

  • Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration.

  • Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments.

  • Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK.

  • Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies.

  • Experience working in or closely supporting a Security Operations Center (SOC).

  • Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications.

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

SAIC is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Share: mail

Apply Now >

Numbers & Facts

LocationWashington, DC
IndustryComputer/IT Services
Salary$80,001–$120,000 Per Year
Company Size10,000 employees or more
Year Founded2013
Websitehttps://jobs.saic.com/

About Company

SAIC is a premier Fortune 500® technology integrator driving our nation's digital transformation. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes secure high-end solutions in engineering, IT modernization, and mission solutions. Using our expertise and understanding of existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions that are critical to achieving our customers' missions. We are a team of 26,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.1 billion. For more information, visit saic.com.

Skills

  • Administrative Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Automationunmatched
  • Bash Scriptingunmatched
  • CIM (Common Information Model)unmatched
  • Cloud Computingunmatched
  • Command Lineunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Comparative Analysisunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • DNS (Domain Name System)unmatched
  • DSL (Digital Subscriber Line)unmatched
  • Data Analysisunmatched
  • Data Qualityunmatched
  • Database Programming Languagesunmatched
  • ElastiCunmatched
  • Elasticsearchunmatched
  • Emerging Technologyunmatched
  • Firewallsunmatched
  • Forwarderunmatched
  • GSEC - GIAC Security Essentials Certificationunmatched
  • HTTP (HyperText Transport Protocol)unmatched
  • HTTPS (HyperText Transport Protocol Secure)unmatched
  • Identify Issuesunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Prevention Systemsunmatched
  • Investigative Reportsunmatched
  • Linux Operating Systemunmatched
  • Microsoft Windows Operating Systemunmatched
  • Network Protocolsunmatched
  • Network Securityunmatched
  • Onboardingunmatched
  • Operational Supportunmatched
  • Operations Processesunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Professional Servicesunmatched
  • Python Programming/Scripting Languageunmatched
  • Query Analysisunmatched
  • REST (Representational State Transfer)unmatched
  • Reporting Dashboardsunmatched
  • Root Cause Analysisunmatched
  • SQL (Structured Query Language)unmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Scripting (Scripting Languages)unmatched
  • Search Engine Optimization (SEO)unmatched
  • Search Technologyunmatched
  • Security Analysisunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Splunkunmatched
  • Systems Administration/Managementunmatched
  • Systems Engineeringunmatched
  • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
  • Technical Writingunmatched
  • Telemetryunmatched
  • Test Plan/Scheduleunmatched
  • Testingunmatched
  • United States Citizenunmatched
  • Use Casesunmatched
  • Windows PowerShellunmatched
  • Work From Homeunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder