Job Description
Salary: 100,000 - 140,000 USD per year Requirements:
- Bachelor’s degree or 4+ additional years of experience in lieu of degree
- 7+ years of cyber experience
- 5+ years working in an Enterprise environment as a cyber engineer, system administrator, or other security personnel
- 3+ years of experience with Splunk Enterprise Security
- Experience with Unix and Windows operating systems
- Experience with network monitoring tools
- Knowledge of network protocols
- DoD 8570 IAT Level II certification or the ability to obtain it within six months of hiring
Responsibilities: - I will be responsible for the day-to-day operation of a large Splunk environment. My tasks will include troubleshooting new and current data collection issues, as well as addressing system issues that may make the system unstable or unusable. I will manage the deployment of all supported and unsupported Splunk add-ons required for specific data sources and will oversee upgrades to all Splunk Enterprise servers. I will integrate with other systems via APIs or other methods and provide documentation such as body of evidence documents, engineering documents, change management documents, system security plans, and accreditation documents. Additionally, I will deliver a comprehensive Splunk deployment document detailing specifications, deployment methods, and architectural considerations for the production environment. I will maintain a strict role-based access control solution around the data collected to ensure a need-to-know ability. My responsibilities also include designing and deploying forwarders rapidly with centralized configuration management, as well as managing Knowledge Object Management and overseeing Enterprise Security configurations and tuning.
Technologies: - Architect
- Bash
- Java
- Network
- Perl
- Python
- Security
- Splunk
- Unix
- Windows
- ASP.NET
- API
More:
Preferred qualifications include experience with scripting languages (such as bash), application development (in Java, Perl, Python, or .NET), and familiarity with databases and analytical tools. Experience with security and operational-related use cases is desired, as well as Holding Splunk certifications such as Architect, Consultant I, Consultant II, Admin, and Power User.
I must possess an active TS/SCI clearance with polygraph. Physically, I should expect to remain in a stationary position 75% of the time, constantly operating a computer and other office productivity machinery, and be able to view and detect information on a computer screen.
Job Tags
Full time,