Ongoing Splunk Professional Services NIH-SS-7360730
Summary
AI-generated · Mar 14, 2026Provide ongoing Splunk professional services to strengthen the organization’s cybersecurity posture by using the Splunk platform to improve visibility, detection, response, and audit readiness across on-premises and cloud environments. Tasks include achieving near real-time visibility into security events, automating detection and reporting of compliance gaps, configuration drift, and vulnerabilities with evidence-based metrics, identifying insider threats and anomalous user behavior through correlation and analytics, enhancing detection of malware and suspicious host/network activity, and developing a Splunk-based Security Profile and Zero Trust Architecture Compliance Dashboard aligned to NIST SP 800-207 and mapped to NIST SP 800-53 controls for audit evidence.
The work is planned as a sole-source award due to the unique qualifications of a specific security engineer from August Schell Enterprises, who has been directly involved in implementing Splunk at the agency for three years; onboarding a new engineer would likely cause delays and increased risk. August Schell Enterprises is the manufacturer, and small businesses may submit capability statements to demonstrate their ability to perform the requirement; a decision to compete this award will be at the government’s discretion based on responses.
Notice of Intent to Sole Source for Ongoing Splunk Professional Services (NIH-SS-7360730) The National Institutes of Health intends to award a Firm-Fixed-Price purchase order to August Schell Enterprises. August Schell Enterprises UEI is PPMBFPRXNAJ9. In accordance with FAR Part 6.302-1, August Schell Enterprises the Contractor is the only known responsible source who can provide the item that meets our standards. No other source has been identified who can provide the requirement listed below. The NLM/LHC aims to strengthen its cybersecurity posture by leveraging the Splunk platform to enhance visibility, detection, response, and audit readiness. Key objectives include: Improve near real-time visibility into security events and system activity across on-premises and cloud environments. Automate detection and reporting of compliance gaps, configuration drift, and security vulnerabilities using evidence-based metrics. Identify insider threats and anomalous user behavior using correlation and behavioral analytics. Enhance detection of malware activity, suspicious host behavior, and network reconnaissance. Develop and maintain a comprehensive Splunk-based Security Profile and Zero Trust Architecture (ZTA) Compliance Dashboard aligned to NIST SP 800-207 and mapped to NIST SP 800-53 controls for audit evidence. This effort requires a sole source award due to the unique qualifications of the identified Security Engineer from August Schell Enterprises. The engineer has been directly involved in the implementation of the Splunk platform within the agency for the past three (3) years. Over this period, he has developed deep institutional knowledge of the agency s cybersecurity environment, data sources, operational requirements, and security monitoring workflows. Given the complexity of the environment and the maturity level of the security content required, onboarding a new engineer would result in significant delays, increased risk, and additional training costs. The incumbent engineer possesses the technical expertise and historical context needed to complete this task effectively and efficiently. Therefore, it is in the best interest of the agency to retain this individual for continuity, quality assurance, and successful delivery of the outlined scope. This notice is not a request for competitive quotes. August Schell Enterprises is the manufacturer. However, any available small businesses (e.g., 8(a), service-disabled veteran owned small business, HUBZone small business, small disadvantaged business, veteran-owned small business, and women-owned small business) as stated herein may submit a written capability statement that clearly supports and demonstrates their ability to perform the requirement. A determination by the Government to compete this proposed award based upon responses to this notice is solely within the discretion of the Government. It is anticipated that an award will be issued approximately ten (10) days after the date of this notice unless the Government determines that another organization has the capability to meet this requirement. Please email responses to Lynda.Cole@nih.gov no later than 10:00 a.m. EST on Thursday March 19, 2026.
From Presolicitation posted on Mar 13, 2026Notice history
1-
Presolicitation LATEST Posted Mar 13, 2026
Details
Award Information
Not yet awarded
Contacts
Agency
Place of Performance
USA