Splunk Systems Administrator

world-globe-glyph
Pensacola, FL
/
Full-time

CSA is looking for a Splunk Systems Administrator in Pensacola, FL to support and enhance our Splunk environment with a strong emphasis on Zero Trust architecture and secure system design. This role requires deep technical expertise in data systems, cybersecurity practices, and secure system administration within classified and unclassified environments. The ideal candidate will play a critical role in advancing our organization’s Zero Trust maturity by leveraging Splunk as a central security analytics and monitoring platform.


For nearly 50 years, CSA has delivered integrated technology and operational support services to meet the defense and federal sector's most complex enterprise needs. Working from operations centers and shipyards to training sites and program offices, CSA deploys experienced teams, innovative tools and proven processes to advance federal missions.


How Your Role Will Make an Impact:

  • Administer and maintain Splunk Enterprise deployments across classified and unclassified environments, ensuring high availability, performance, and security. 
  • Architect and implement Splunk solutions that support Zero Trust principles, including continuous monitoring, least privilege access, and micro-segmentation visibility. 
  • Integrate diverse log sources (endpoints, network devices, identity systems, cloud services) to enable comprehensive visibility aligned with Zero Trust architecture. 
  • Develop and optimize correlation searches, alerts, and dashboards to detect anomalous behavior, insider threats, and policy violations. 
  • Support  implementation of Zero Trust frameworks by enabling telemetry for identity, device posture, and access control validation. 
  • Manage and enhance services within Splunk IT Service Intelligence (ITSI) to align operational intelligence with security posture. 
  • Collaborate  with cybersecurity teams to map Splunk capabilities to frameworks such as NIST 800-207 (Zero Trust Architecture). 
  • Provide  advanced support to Splunk users, including search development, data  onboarding, and dashboard creation for security and operational use cases.      
  • Harden and secure Linux-based systems in accordance with DISA STIGs and organizational security policies. 
  • Automate system administration, data ingestion, and security workflows using scripting languages such as Python, Bash, or PowerShell. 
  • Participate in incident response and threat hunting activities using Splunk as a primary investigative tool. 

    

What You Will Need to Join Our Award-Winning Team:

  • Clearance: Must possess  and maintain an active Secret Clearance or have the ability to obtain and  maintain one. 
  • Certification: CompTIA  Security+ (Sec+) or qualifying Bachelor’s degree in a related field and meet U.S. Navy Cybersecurity Workforce (CSWF) requirements. 
  • Minimum of 6+ years of experience in systems administration, including implementation of DISA STIGs. 
  • Hands-on experience administering Splunk Enterprise in distributed environments (indexers, search heads, forwarders). 
  • Familiarity with Zero Trust concepts, such as identity-centric security, continuous verification, and least privilege access. 
  • Experience onboarding and normalizing logs from multiple data sources (e.g., Active Directory, firewalls, EDR tools, cloud platforms). 
  • Experience with automation and scripting (Python, Bash, or PowerShell). 
  • Working knowledge of Linux system administration and security hardening. 

Preferred Qualifications:

  • Experience implementing or supporting Zero Trust Architecture (ZTA) in a DoD or federal environment. 
  • Familiarity with frameworks such as NIST 800-207, RMF, and MITRE ATT&CK. 
  • Experience with Splunk Enterprise Security (ES) and/or ITSI. 
  • Knowledge of identity and access management (IAM), multi-factor authentication (MFA), and endpoint security integration. 
  • Splunk certifications (e.g., Splunk Enterprise Certified Admin, Splunk Core Certified Power User). 
  • Experience with cloud platforms (AWS, Azure, or GovCloud) and their integration into Splunk. 


This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice.

Applicants may need to meet eligibility requirements for access to classified information; an active United States Department of Defense security clearance or the ability to obtain one may be required for this role.

As a federal contractor, CSA will abide by the client’s infectious disease protocols.

WE BELIEVE great companies know who they are and what they stand for. CSA’s common purpose and core values were purposefully developed to create a culture focused on unlocking the full potential of our people—so they are inspired to solve our clients’ toughest challenges. It’s no secret, we owe the past 18 years of our success to our outstanding and ambitious team members. To support our hard working team, we offer an environment focused on learning and growth, an awesome benefits package, and opportunities to build a long and successful career.

We are constantly on the hunt for talented, forward-thinking problem solvers with an energetic attitude and a strong work ethic to join our elite team of CSAers.  

Be a part of CSA … do  great  things!

CSA is a Federal Contractor and an Equal Opportunity/Affirmative Action Employer.

If you are an individual with a disability and would like to request a reasonable workplace accommodation for any part of our employment process, please send an email to  hr@csaassociates.com. Please indicate the specifics of the assistance needed. Assistance is reserved for individuals who are requesting a reasonable workplace accommodation. It is not intended for other purposes or inquiries. We’re an equal opportunity employer that empowers our people no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or veteran status or other protected characteristic.

Federal Equal Opportunity is the Law
Federal Employee Rights under FMLA
Federal Employee Polygraph Protection Act
E-Verify Participation Poster (uscis.gov)
If you are a California resident applying for a job, you consent to our  California Job Applicant Privacy Notice .

Notification for current or previously cleared professionals:

Official U.S. Government information appearing in the public domain shall not automatically be considered UNCLASSIFIED or approved for public release. CSA recognizes that information contained in resumes of current or previously cleared professionals may be sensitive, contain potentially proprietary and/or protected information. Protected Information is considered classified, in the process of a classification determination, or unclassified, but protected by statute. Therefore, all resumes should be approved for public release by a U.S. Government Official with Original Classification Authority, prior to posting the resume to CSA’s applicant tracking system.
By submitting my resume, I understand that I am NOT authorized to upload content with Official U.S. Government information that is considered, sensitive, proprietary, or protected.