1748 IT & Software Developer jobs in the US

Senior Splunk Engineer
$140,000 - 175,000
Cherokee Federal
Dawes Avenue 5000, Alexandria
$140,000 - 175,000
Requirements
Must:
- 7+ years in security engineering, SOC/IR, or platform engineering, with at least 4 years focused on designing and managing Splunk Enterprise and Splunk ES in production settings.
- 3+ years of hands-on experience with Splunk SOAR (Phantom) and automating ES notable events as well as ServiceNow IR workflows.
- Substantial knowledge of AWS services: GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs; cross-account and multi-region experience is preferred.
- Proven experience in integrating ServiceNow for Incident Response.
- Proficient in SPL, Python, AWS Boto3, Splunk/Phantom SDKs, REST APIs, and Git-based version control systems.
- Strong understanding of CIM standards, data model accelerations, indexing/retention strategies, and tuning search performance.
- In-depth familiarity with MITRE ATT&CK, CVE/CVSS, CISA KEV, and frameworks for risk-based detection and automation.
- Experience in aligning operations with FISMA/NIST RMF, FedRAMP, and CMMC standards; adept with evidence collection and audit support.
- Preferred: Relevant Splunk certifications (Core Certified Power User/Admin/Architect, ES Admin), AWS certifications, Security+, CySA+, CISSP, GCDA/GCSA.
- Preferred: Background in managing Splunk SHC, DS/Deployer, KVstore, and ES content management at scale alongside AWS Organizations and ServiceNow IR customization/change management integrations.
- Must fulfill pre-employment qualifications of Cherokee Federal.
Responsibilities
- Design, implement, and sustain Splunk Enterprise, including indexers, search heads (SHC), cluster masters, deployment servers, and forwarders across both on-premises and AWS environments.
- Create scalable data onboarding pipelines, ensuring proper parsing and indexing through props/transforms, HEC, UF/HF, and S3/SQS/SNS-based ingestion.
- Enforce role-based access control (RBAC), manage data retention, and maintain index strategies and knowledge object governance in compliance with federal regulations.
- Enhance search performance, accelerate data models, optimize KV store usage, and improve notable event throughput and latency in ES.
- Develop and refine ES correlation searches, risk-based alerting, and adaptive response actions in line with MITRE ATT&CK frameworks.
- Construct dashboards, conduct investigations, and streamline notable event workflows to minimize false positives and boost analyst efficiency.
- Uphold CIM-compliant data models and spearhead normalization and data quality initiatives across various data sources like cloud, endpoint, and network.
- Evaluate and report on the effectiveness of detection and response initiatives (MTTR, precision/recall, RBA risk scores, SLA adherence).
- Design Splunk SOAR (Phantom) playbooks and applications with secure, scalable structures for threat triage, enrichment, and containment.
- Coordinate ES notable events with automated triage and ServiceNow IR for incident generation, enrichment, SLA management, approvals, and documentation.
- Develop AWS-centric detection and response strategies utilizing tools like GuardDuty, CloudTrail, and Security Hub; implement secure actions with necessary human approval processes.
- Merge EDR and identity management platforms for host containment, IOC blocking, and remote response capabilities through APIs.
- Lead Splunk deployments in AWS, focusing on scalability, multi-account and multi-region data ingestion, and cross-account automation through Boto3 and native services.
- Standardize reusable Python modules, optimize SDK usage, and implement CI/CD best practices for application packaging and version management.
- Align controls with FISMA/NIST RMF, FedRAMP, and CMMC requirements, ensuring continuous audit-readiness through comprehensive logging and approval tracking.
- Oversee updates on Plans of Action and Milestones (POA&M), validate controls, and manage continuous monitoring dashboards.
- Advocate for secrets management, least privilege access, and safe-response protocols throughout platform and automation development.
- Convert SOC/IR playbooks (e.g., phishing response, malware handling) into reliable detection and automation strategies.
- Mentor junior engineers and analysts, sharing expertise in SPL, ES content creation, CIM principles, and SOAR playbooks.
- Collaborate with stakeholders to prioritize use cases and deliver measurable results.
- Perform additional duties as required.
Description
We are Criterion, part of Cherokee Federal, a division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted collaborator for over 60 federal clients, we are dedicated to creating a brighter future, tackling complex challenges, and serving the governments mission with compassion and dedication. We offer a competitive salary commensurate with experience along with comprehensive benefits, including Medical, Dental, Vision, and 401K. Our work environment is inclusive, and we actively encourage veterans and transitioning military personnel to apply. Join us to drive innovation and enhance our security posture.
Something wrong or incorrect with this job? Tell us in the chat 💬 on the right ➡️
You can find DevOps salaries in the United States here.
How many DevOps jobs are in the United States?
Currently, there are 1748 DevOps openings. Check also: Cloud jobs, AWS jobs, Azure jobs, GCP jobs, Kubernetes jobs, Docker jobs, Terraform jobs - all with salary brackets.
Is the US a good place for DevOps?
The US is one of the best countries to work as a DevOps. It has a vibrant startup community, growing tech hubs and, most important: lots of interesting jobs for people who work in tech.
Which companies are hiring for DevOps jobs in the United States?
Novatek International, Dulcedo Management, CA Tuning, Archon Systems Inc, DataAnnotation, MORSE Corp, Tek84 Inc. among others, are currently hiring for DevOps roles in the United States.
The company with most openings is Jobot as they are hiring for 277 different DevOps jobs in the United States. They are probably quite committed to find good DevOps.
The company with most openings is Jobot as they are hiring for 277 different DevOps jobs in the United States. They are probably quite committed to find good DevOps.