user avatar

SIEM Data Onboarding Engineer (Cyber Engineer - Mid LCAT)

Ennoble First

Posted today
Top Secret/SCI
$120,000 - $150,000
Polygraph
IT - Database
Reston, VA (On-Site/Office)

SIEM Data Onboarding Engineer (Cyber Engineer - Mid LCAT)

Location: College Park, MD; Washington, DC; Reston, VA; Colorado Springs, CO; Norfolk, VA

Required Clearance: Active TS/SCI with polygraph eligibility

Employment Type: Full-Time Regular

Shift: Day

Travel: No

Relocation Assistance: Yes

Company Overview

We are Ennoble First. The people supporting and securing some of the most complex government, defense, and intelligence projects across the country. We ensure today is safe and tomorrow is smarter. Our work has meaning and impact on the world around us, but also on us, and that's important. Ennoble First is your place. You make it your own by embracing autonomy, seizing opportunity, and being trusted to deliver your best every day. We think. We act. We deliver.

Job Description

Ennoble First is seeking a SIEM Data Onboarding Engineer to support the design, deployment, and sustainment of enterprise SIEM capabilities in a highly regulated mission environment. This role focuses on onboarding, parsing, normalizing, enriching, and routing security telemetry into Splunk to support detection, investigation, and response operations across on-premises and cloud environments. The engineer partners with security operations, platform engineering, and data owners to ensure consistent, high-quality data ingestion and analytics readiness.

Primary Responsibilities
  • Design, deploy, and manage Splunk SIEM infrastructure including indexers, search heads, forwarders, and deployment servers
  • Build and maintain data onboarding pipelines for enterprise systems, applications, and security tools
  • Develop and maintain Splunk configurations including props.conf, transforms.conf, inputs.conf, outputs.conf, and Splunk Apps/TAs
  • Configure and manage Cribl sources, destinations, routes, collectors, and pipelines
  • Parse, normalize, enrich, mask, deduplicate, and route data to Splunk and downstream platforms
  • Develop and maintain SPL searches, dashboards, alerts, and validation queries
  • Monitor and troubleshoot SIEM performance, ingestion latency, parsing errors, and data quality issues
  • Collaborate with security operations and engineering teams to support detection engineering requirements
  • Implement best practices for indexing strategy, data retention, and platform scalability
  • Produce documentation and provide operational support for SIEM workflows

Required Qualifications

  • Bachelor's degree and 5+ years of experience supporting IT or cybersecurity projects and activities
  • Experience managing and configuring Splunk SIEM environments
  • Experience with Splunk architecture including indexers, search heads, forwarders, and deployment servers
  • Experience using Splunk REST APIs for automation and operational tasks
  • Experience configuring Cribl sources, destinations, routes, collectors, and pipelines
  • Experience building pipelines to parse, normalize, enrich, mask, deduplicate, and route data
  • Experience authoring and maintaining Splunk configuration files and packaging Apps/TAs
  • Experience administering Linux and Windows systems including services, permissions, file paths, and log locations
  • Experience using regex for field extraction and event breaking
  • Active TS/SCI clearance; willingness to take a polygraph exam

Certifications

  • Active DoD 8570 Information Assurance Technician (IAT) Level II certification (e.g., Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND)
  • Must obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date

Additional Qualifications

  • Experience working in regulated environments using DISA STIGs or organizational hardening standards
  • Strong understanding of networking fundamentals including TCP/UDP, TLS, syslog transport, and firewall ports
  • Experience troubleshooting with tools such as tcpdump or Wireshark
  • Familiarity with common log formats including syslog, Windows Event Logs, JSON, CSV, and XML
  • Proficiency with SPL for validation, troubleshooting, and dashboard development
  • Experience with scripting languages such as Python, Bash, or PowerShell
  • Familiarity with Git and Ansible automation workflows
  • Strong written and verbal communication skills

Compensation

Salary range: $120,000 - $150,000

The Ennoble First pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered include responsibilities of the role, education, experience, knowledge, skills, internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Equal Employment Opportunity

Ennoble First is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by federal, state, or local law.

E-Verify Participation

Ennoble First participates in the U.S. Department of Homeland Security's E-Verify program to confirm the employment eligibility of all newly hired employees. E-Verify is a registered trademark of the U.S. Department of Homeland Security.

Ennoble First is committed to providing a diverse and inclusive work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Ennoble First participates in E-Verify.

The information below will be listed on our website's careers landing page.

EEO is the Law | Pay Transparency Nondiscrimination

www.dhs.gov/E-Verify

E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.
group id: 90783838

At Ennoble First, we’re proud to serve and partner with leading federal agencies—including the DoD, NGA, U.S. Air Force, U.S. Army, DIA, Department of State, and U.S. Cyber Command—as well as trusted industry innovators like AWS, Lockheed Martin, Northrop Grumman, Booz Allen, CACI, Leidos, and Splunk. Together, we deliver secure, agile IT solutions that advance intelligence, defense, healthcare, and national security.  What sets us apart is our people. We believe in empowering bold thinkers, fostering collaboration, and creating an environment where health, family, and work stay in balance. We embrace diverse perspectives, encourage innovation, and ensure every team member feels supported and connected.  When you join Ennoble First, you’re not just filling a role—you’re becoming part of a community that values you, challenges you, and helps you grow while making an impact on missions of national importance.

job ad image
Find Ennoble First on Social Media
Network Employers
user avatar
About Us
Ennoble First is a high-tech solutions and services company dedicated to supporting the nation’s most critical missions. We partner with federal agencies across defense, intelligence, national security, and healthcare, delivering agile, data-driven technologies that enhance efficiency, reduce risk, and empower smarter decisions.  Our expertise spans data engineering and management, intelligent automation, enterprise systems, advanced cybersecurity, research and development, and strategic talent support. These capabilities allow us to address today’s complex challenges while preparing organizations for the threats and technologies of tomorrow.  Trusted by agencies such as the Department of Defense, U.S. Cyber Command, and leading federal health organizations—as well as top industry partners—we’re known for providing secure, innovative, and mission-focused solutions that make a real impact. At Ennoble First, we don’t just deliver technology—we help safeguard the future.
job ad2 image

Ennoble First Jobs


Job Category
IT - Database
Clearance Level
Top Secret/SCI