Ft. Meade, VA
Candidate must have a Top Secret security clearance.
Our client is seeking a Splunk specialist to support the DoD' s JRSS (Joint Regional Security Stack) deployment activities, a multi-year, global effort to improve the DoD' s security posture and provide enhanced security capabilities and analytics by centralizing and virtualizing network security into regional stacks rather than locally distributed appliances.
Day to Day Responsibilities:
In this role, the engineer will act as the senior support person for Splunk. In this capacity you will work as part of a multi-disciplinary team that supports the active and passive Computer Network Defense (CND) tools deployed in stacks. The engineer will also integrate with other technical teams, with DISA personnel, with vendor technical support personnel, and with technical representatives from DoD services.
The Splunk Engineer should have a strong Splunk Admin background to support Splunk platform. Additionally, a strong Splunk development background is desired. The responsibilities, include data onboarding (including syslog), troubleshooting multi-clustered Splunk Enterprise environments, assist internal Splunk users on query optimization and visualization, write complex regex for field extractions and build data models.
Day to day responsibilities may include:
- Onboarding Splunk ES critical data sources - ingestion of critical data sources/data logs from the enterprise into the SIEM (Security Information Event Management) tool to meet the Splunk ES (Enterprise Security) implementation
- Normalizing Log Data to CIM (Common Information Model) as required by Splunk ES (Enterprise Security) to meet the provided security use cases (Rules/Alerts)
- Create viewable Splunk dashboards to provide visibility into ingested log data
- Create alerts that trigger/activate on configured setting to deploy or sends a note/email/attachments to a particulate destination email or groups
- Create security rules (alerts) that trigger on anomalous activities or threat detections
- Splunk Support - Assisting Customers with any issues when ingestion of logs that are not working properly. Or, communication issues with Splunk.
- Resolving Splunk infrastructure or system issues
- Experience with architecting in Splunk. Designing and implementing changes
- Deep understanding of Splunk and interacting as more than just a user
- Experience with customizing and configuring the tool based on customer needs
- Bachelor’ s Degree and 8 years of relevant experience (work experience may be substituted for degree)
- IAT Level II 8570 Certification
- Prior experience as a network intrusion analyst or Security Operations Center analyst.
- Experience configuring and maintaining the tool in a multi-tenant environment using VLANs to differentiate customers’ traffic
- Splunk Administrator Certification
- Splunk Developer certification
- Experience with one or more of the other CND tools in the JRSS cyber suite:
- Tipping Point
- ELK tools
Job Type: FT