Splunk engineer with Security Clearance
Company: Base One Technologies
Location: Arlington
Posted on: May 5, 2024
|
|
Job Description:
Primary Responsibilities Our govt client is seeking a talented
Splunk Engineer to join our team to support a new customer on a
highly-visible and strategic Cybersecurity Task OrderThe Splunk
Engineer will be a member of the Cybersecurity Engineering team and
will install and maintain Splunk infrastructure, gather
requirements from customers, onboard data, and assist end users
with search, dashboards, reports, and knowledge objects.
--- Manage multiple assignments, changing priorities, and work
independently with little oversight
--- Build, implement, and administer Splunk in Windows and Linux
environments
--- Work with existing and custom Splunk applications and add-ons
to fulfill customer needs
--- Provide operations and maintenance support for a distributed
Splunk environment consisting of heavy forwarders, indexers, and
search head servers, spanning security, performance, and
operational roles
--- Editing and maintaining Splunk configuration files and apps
--- Onboard data to Splunk via forwarder, scripted inputs, TCP/UDP,
and modular inputs from a variety of sources.
--- Provider operational support for Splunk Universal Forwarder on
Linux and Windows endpoints
--- Manage, and support automation solutions for Splunk deployment
and orchestration in on-premise and cloud environments
--- Documentation, reporting, presentation, teamwork, and DHS wide
collaboration are among the expected duties and mission of the task
order Required Education/Experience
Bachelor's degree in Computer Science, Engineering, or a related
field and a minimum of six (6) years of experience in system
administration, database administration, network engineering,
software engineering, or software development, Cybersecurity Basic
Qualifications
Bachelor's degree in Computer Science, Engineering, or a related
field and a minimum of six (6) years of experience in system
administration, database administration, network engineering,
software engineering, or software development, with a concentration
in Cybersecurity
--- Four (4) years of experience with Splunk in distributed
deployments --- Current Splunk Enterprise Certified Admin
certification --- Excellent written and oral skills, ability to
work closely with multiple customers, manage expectations and track
engagement scope --- Experience with Splunk Enterprise Security or
integration with other Security Information and Event Management
(SIEM) platforms --- Proficient at data on-boarding activities
including routing, parsing, and normalizing events to the Splunk
Common Information Model (CIM) --- Proficiency onboarding data
using Splunk developed add-ons for Windows, Linux, and common
third-party devices and applications --- Experience onboarding data
into Splunk via forwarder, scripted inputs, TCP/UDP, and modular
inputs from a variety of sources --- Proficiency managing Splunk
using the Splunk command-line interface--- Proficiency managing
Splunk using configuration files --- Experience collaborating with
separate engineering teams to configure data sources for Splunk
integration --- Proficiency implementing and onboarding data in
Splunk DB Connect --- Experience with Splunk performing systems
administration, including performing installation, configuration,
monitoring system performance and availability, upgrades, and
troubleshooting --- General networking and security troubleshooting
(firewalls, routing, NAT, etc.) --- Splunk implementation and
troubleshooting experience --- Experience in managing, maintaining,
and administering multi-site indexer cluster --- Proficiency
developing log ingestion and aggregation strategies per Splunk best
practices --- Perform integration activities to configure, connect,
and pull data with 3rd party software APIs --- Proficient in
regular expressions --- Ability to autonomously prioritize and
successfully deliver across a portfolio of projects --- DHS Entry
on Duty (EOD) is required to support this program Must Have One of
the Following J3 Certifications
CASP, GCIH, GCWN, GISF, GISP, GSSP, GICSP, GSSP, SEI, CISSP, CCSP,
CSSLP, SSCP, CCNP, CCNP Security, CCIE Security, CEH, ECSP, MCSE,
RHCA, RHCE, VCP, VCAP, VCIX, VCDX Preferred Qualifications
--- Experience working in Azure --- Experience with GitLab or
GitHub or other version control system --- Scripting and
development skills (Bash, Python, and PowerShell)
Keywords: Base One Technologies, Annandale , Splunk engineer with Security Clearance, Engineering , Arlington, Virginia
Click
here to apply!
|