Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Washington, DC, United States
Posted
Yesterday
SQLLogstashSplunkTCP/IPBashDNSHTTPHTTPSKibanaOnboardingPowerShellPythonREST
Job Description
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline (4 years experience in lieu of degree)
- 5+ years experience relevant IT/cybersecurity experience.
- 3+ years of hands-on SIEM administration experience supporting enterprise or similarly complex environments.
- Hands-on experience with Splunk Enterprise, including SPL, data ingestion, forwarders, indexes, searches, dashboards, alerts, and platform troubleshooting.
- Experience onboarding and troubleshooting enterprise log sources and understanding telemetry flow from source systems through collection, ingestion, indexing, and search.
- Working knowledge of SQL and experience querying data for analysis, troubleshooting, validation, or reporting.
- Experience with or working knowledge of Elastic, Elasticsearch, Kibana, or comparable search and analytics technologies, with the ability to rapidly develop deeper Elastic expertise.
- Understanding of enterprise logging concepts, including collection, parsing, normalization, enrichment, indexing, retention, and data quality.
- Strong Linux command-line skills and working knowledge of Windows/Linux systems, networking, and common protocols such as TCP/IP, DNS, HTTP/HTTPS, TLS, and syslog.
- Familiarity with enterprise cybersecurity technologies such as EDR, firewalls, IDS/IPS, identity systems, and vulnerability management platforms.
- Demonstrated ability to independently troubleshoot technical problems, analyze unfamiliar data, test assumptions, identify root causes, and develop practical solutions.
- Strong technical curiosity, ownership, accountability, and ability to learn new technologies, platforms, and query languages.
- Strong written and verbal communication skills with the ability to document technical processes and collaborate effectively across teams.
Preferred Qualifications
- Hands-on experience with Elastic Stack / Elastic Security, including Elasticsearch, Kibana, Elastic Agent/Fleet, Beats, or Logstash.
- Experience with KQL, ES|QL, EQL, Query DSL, or comparable search and analytics languages.
- Experience supporting a SIEM migration, particularly Splunk-to-Elastic or a comparable enterprise migration.
- Experience with Splunk ES, Splunk CIM, Elastic Common Schema (ECS), or distributed Splunk environments.
- Experience with security detection engineering, correlation rules, alert tuning, threat hunting, or MITRE ATT&CK.
- Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, or similar technologies.
- Experience working in or closely supporting a Security Operations Center (SOC).
- Relevant technical certifications such as Splunk, Elastic, Security+, CySA+, GSEC, or comparable certifications.
Similar jobs
- UG
Part Time Patient Access Representative
NewUnitedHealth Group
Maplewood, MN🇺🇸$16 - $29/hrOn-site2 days agoMicrosoft OfficePatient CarePharmacy+1 - UG
Registration Representative
NewUnitedHealth Group
Scarborough, ME🇺🇸$16 - $29/hrOn-site2 days agoComplianceMedical TerminologyMicrosoft Office+2 - UG
Specimen Processor
UnitedHealth Group
NEEDHAM, MA🇺🇸$16 - $29/hrHybrid5 days agoComplianceMedical TerminologyPharmacy+3 - UG
Part Time Patient Access Representative
UnitedHealth Group
Oakdale, MN🇺🇸$16 - $29/hrOn-site2 weeks agoMicrosoft OfficePatient CarePharmacy+1 - UG
Part Time Patient Access Representative Associate
UnitedHealth Group
Saint Louis Park, MN🇺🇸$16 - $29/hrOn-site2 weeks agoCall CenterMicrosoft OfficePharmacy+1 - UG
Patient Access Representative Associate
UnitedHealth Group
MINNEAPOLIS, MN🇺🇸$16 - $29/hrOn-site4 weeks agoCall CenterMicrosoft OfficePharmacy+1