Senior Splunk SIEM/SOAR & Security Analytics / AI-ML Engineer
Company: Technology & Bussiness Managment Inc.
Location: Remote (Remote)
Salary: $145,000 - $155,000 a year
Type: Full-time
Remote: Yes
Posted: 2026-09-27
About this role
US Based Position. Must be US Citizen.
Location: Arlington VA(U.S.-based). Remote Work Allowed in US.
Employment Type: Full-Time
Company: Technology & Business Management, Inc. (TBM Inc.)
Experience Level
8+ years in security analytics/SIEM engineering with 4+ years of advanced Splunk engineering; hands-on dashboarding, SPL, alerting, data onboarding, and automation required.
Position Summary
Own DLP telemetry, analytics, dashboards, alerting, automation, and measurable optimization in Splunk, while supporting Government-approved SOAR/RPA and bounded AI/ML use cases.
Key Responsibilities
Engineer and maintain Splunk ingestion, normalization, searches, dashboards, reports, alerts, health metrics, event-volume trends, and operational/executive DLP reporting.
Develop SPL queries and documented calculations that Government personnel can reproduce and sustain.
Integrate telemetry from Symantec/Broadcom, Purview, Palo Alto, and other authorized DLP/security platforms.
Design automated notifications, alerts, alarms, and Government-authorized SOAR/RPA workflows to reduce manual triage and improve response.
Support event correlation, incident analytics, severity/prioritization, trend analysis, and detection-performance measurement.
Evaluate approved AI/ML-enabled capabilities to reduce false positives, identify notable events, improve triage, and reduce analyst workload; establish baseline/candidate comparisons and rollback criteria.
Track metrics such as false positives, false negatives where measurable, alert volume, time-to-triage/disposition, stability, workload, and business impact.
Document data definitions, dashboard maintenance, automation logic, model/configuration tuning, test evidence, limitations, procedures, and Government training.
Required / Critical Skills
Splunk Enterprise / Splunk ES; SPL; dashboards; data models; alerts; field extraction; ingestion/onboarding; CIM; APIs; security analytics; incident correlation.
Splunk ...