Technology & Bussiness Managment Inc.
Senior Splunk SIEM/SOAR & Security Analytics / AI-ML Engineer
Share this job
Job Description
US Based Position. Must be US Citizen.
Location
Arlington VA(U.S.-based). Remote Work Allowed in US. Employment Type: Full-Time Company: Technology & Business Management, Inc. (TBM Inc.)
Experience Level
8+ years in security analytics/SIEM engineering with 4+ years of advanced Splunk engineering; hands-on dashboarding, SPL, alerting, data onboarding, and automation required.
Position Summary
Own DLP telemetry, analytics, dashboards, alerting, automation, and measurable optimization in Splunk, while supporting Government-approved SOAR/RPA and bounded AI/ML use cases.
Key Responsibilities
Engineer and maintain Splunk ingestion, normalization, searches, dashboards, reports, alerts, health metrics, event-volume trends, and operational/executive DLP reporting.
Develop SPL queries and documented calculations that Government personnel can reproduce and sustain.
Integrate telemetry from Symantec/Broadcom, Purview, Palo Alto, and other authorized DLP/security platforms.
Design automated notifications, alerts, alarms, and Government-authorized SOAR/RPA workflows to reduce manual triage and improve response.
Support event correlation, incident analytics, severity/prioritization, trend analysis, and detection-performance measurement.
Evaluate approved AI/ML-enabled capabilities to reduce false positives, identify notable events, improve triage, and reduce analyst workload; establish baseline/candidate comparisons and rollback criteria.
Track metrics such as false positives, false negatives where measurable, alert volume, time-to-triage/disposition, stability, workload, and business impact.
Document data definitions, dashboard maintenance, automation logic, model/configuration tuning, test evidence, limitations, procedures, and Government training.
Required / Critical Skills
Splunk Enterprise / Splunk ES; SPL; dashboards; data models; alerts; field extraction; ingestion/onboarding; CIM; APIs; security analytics; incident correlation.
Splunk SOAR or comparable orchestration/automation; Python or scripting; REST APIs; JSON; data normalization.
Understanding of DLP events/policies, SOC workflows, detection engineering, false-positive reduction, and security KPIs.
Practical AI/ML analytics knowledge with emphasis on explainability, human review, validation, privacy/security controls, and measurable benefit rather than custom model research.
Splunk Core Certified Power User/Admin/Architect or Splunk Enterprise Security certification strongly preferred.
Preferred Qualifications
Experience with Qmulos, federal continuous monitoring/FISMA reporting, or large federal Splunk environments.
Experience integrating DLP products into SIEM/SOAR workflows.
Current Public Trust/MBI or clearance.
Education
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Information Systems, or a related field is preferred. Equivalent directly relevant experience and advanced industry certifications may be considered, subject to the applicable contract labor-category requirements.
Federal Suitability / Security
Candidate must be able to meet IRS personnel-security and suitability requirements for the position, including the applicable background investigation and required security/privacy training. A current favorably adjudicated federal Public Trust/MBI or other investigation that may qualify for reciprocity is highly desirable.
What Will Make a Candidate Stand Out
Direct hands-on experience with the named platform(s), not only governance or oversight.
Recent enterprise production experience supporting sensitive or regulated information.
Ability to explain specific examples of troubleshooting, policy/rule tuning, testing, incident support, measurable improvement, and documentation.
Federal customer experience and demonstrated ability to work within controlled access, change, audit, and documentation processes.
Ability to become productive quickly and communicate effectively with both engineers and Government stakeholders.
Why Join TBM Inc.
- Support high-impact federal missions
- Work on strategic IT modernization programs
- Join a fast-growing federal consulting firm
- Collaborate with experienced government and industry leaders
- Opportunity to grow into senior consulting and portfolio management roles
How to Apply
Interested candidates should apply via Indeed with their resume. Qualified applicants will be contacted for next steps.
TBM Inc. is an equal opportunity employer.
All qualified applicants will receive consideration without regard to race, color, religion, sex, national origin, disability, or veteran status.
Job Type: Full-time
Pay: $145,000.00 - $155,000.00 per year
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Employee discount
- Flexible schedule
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Referral program
- Retirement plan
- Tuition reimbursement
- Vision insurance
Work Location: Remote
Keep looking
Similar Remote Jobs That Pay Well
Technology & Bussiness Managment Inc.
Senior Palo Alto DLP & Cloud Security Engineer
Booz Allen Hamilton
AI/ML Data Architect
Booz Allen Hamilton
AI/ML Data Architect
CSAA Insurance Group, a AAA Insurer