Senior Information System Security Engineer
Job Description
The Senior Information System Security Engineer position supports Splunk deployments in classified environments within MITRE’s Cybersecurity Risk Management Department. The role focuses on engineering, securing, and operating Splunk while meeting audit and compliance expectations in support of inspections and mission stakeholders.
Role Location and Work Schedule
- Location: Bedford, MA
- Work mode: Onsite
- On-site requirement: 5 days a week onsite
Compensation
- Salary range: USD 129,200 - 193,800 per year
- Midpoint and structure: $129,200 - $161,500 - $193,800 Annual
Summary
This role provides senior-level support for Splunk in classified environments. Responsibilities include engineering and securing Splunk deployments, integrating data sources, creating dashboards and alerts using SPL, and ensuring compliance with Security Technical Implementation Guides (STIG) and audit requirements. The position also includes support for external inspections and coordination with sponsors and department stakeholders.
Key Responsibilities
- Design, deploy, and maintain Splunk environments, including clusters, indexers, and forwarders, with a focus on high availability, scalability, and performance.
- Identify and integrate new data sources into Splunk by creating and managing data inputs, indexes, and source types.
- Develop custom dashboards, apps, reports, and alerts using SPL to visualize trends and enable actionable insights.
- Monitor Splunk health, troubleshoot issues, and optimize search performance and data retention policies.
- Partner with end-users to gather requirements, assist with searches, and provide training on Splunk usage and best practices.
- Collaborate with IT, security, and other teams to support business needs.
- Ensure security of the Splunk environment, including managing security updates, patching vulnerabilities, resolving STIG findings, and using Splunk for security event monitoring and incident response support.
- Design and develop Splunk dashboards and alerts aligned with NIST 800-53 audit requirements for monitoring and reporting.
- Coordinate with System Administrators and Information System Security Officers/Managers to maintain Splunk operations.
- Work with logs from Windows, Linux, Palo Alto, and Cisco systems to ensure accurate data ingestion for operational monitoring and security alerting.
- Apply strong problem-solving skills to define mitigation strategies and ensure Splunk systems operate in compliance with STIG requirements.
- Manage Splunk user roles and permissions, authentication mechanisms, configuration files, data inputs, and forwarders.
- Own the analysis, integration, testing, operations, and maintenance activities for Splunk system security.
- Assist during external security inspections and support compliance for Splunk environments across the department.
Required Qualifications
- Experience and education: Typically requires a minimum of 5 years of related experience with a Bachelor’s degree; or 3 years with a Master’s degree; or a PhD with relevant experience who can immediately contribute; or an equivalent combination of related education and work experience.
- Deep understanding of Splunk architecture, administration, and management on Linux and Windows infrastructure.
- Proficiency in scripting languages including Python, Bash, or PowerShell to automate Splunk-related tasks.
- Strong analytical and problem-solving skills for troubleshooting complex issues in large-scale distributed systems.
- Hands-on experience with medium to large enterprise Splunk environments.
- Knowledge of classified infrastructure and the A&A process.
- Ability to clearly communicate complex technical concepts to technical and non-technical audiences.
- Self-starter approach with the ability to coordinate with stakeholders across multiple teams to complete projects.
- Must meet DoD 8570.01M IAM Level III requirements.
- Security clearance: Must have an active Top Secret/SCI U.S. Government issued Security Clearance and be able to obtain and maintain a Top Secret/SCI w/Poly U.S. Government issued Security Clearance. U.S. citizenship is required for consideration per U.S. Government eligibility requirements.
- Onsite schedule: 5 days a week onsite.
Technologies
- Splunk
- SPL
- Python
- Bash
- PowerShell
- Linux
- Windows
- Palo Alto
- Cisco
Preferred Qualifications
- Active TS/SCI with CI Poly Security Clearance.
- Experience with SPL, data onboarding, custom apps, and creating visualizations.
- Knowledge of emerging IT and cybersecurity technologies.
- Experience with Windows, RHEL, virtualization, and networking within enterprise environments.
- Proven ability to advise senior leadership on risk levels, security posture, and policy changes.
- Previous experience operating as a SCI/SAP ISSO, ISSE, System Administrator, or ISSM.
- Ability to mentor junior staff and foster a collaborative team environment.
- Familiarity with insider threat programs and strategies for mitigating insider risks.
Clearance Requirements
- Required clearance to apply: Top Secret/SCI
- Must have or obtain within one year of hire: Top Secret/SCI/Polygraph