Why This Role Stands Out
You will play a critical role in enhancing federal cybersecurity defenses by managing and optimizing Splunk environments, offering significant opportunities for professional growth and skill development. This hybrid role is ideal for experienced cybersecurity professionals with a strong background in SIEM platforms and a knack for problem-solving, allowing you to contribute to vital national security initiatives. Apply today to join a reputable organization and make a tangible impact.
Quick Overview
Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
Herndon, VA, United States
Posted
7 weeks ago
AWSSplunkTCP/IP
Job Description
Responsibilities include but are not limited to
- Troubleshoot new and existing data collection issues to ensure accurate and reliable ingestion of security-relevant data.
- Diagnose and resolve system issues that impact stability, performance, or usability.
- Deploy, manage, and maintain supported and unsupported Splunk Add-ons required for specific data sources.
- Develop and maintain documentation, including Body of Evidence (BOE) artifacts, engineering documentation, change management records, system security plans, and accreditation materials, as required.
- Deliver a comprehensive Splunk deployment document detailing specifications, deployment methods, and architectural considerations for production environments.
- Implement and maintain strict role-based access control to ensure data is accessible on a validated need-to-know basis.
- Design and deploy Splunk forwarders using centralized configuration management through the Splunk Deployment Server to support rapid and consistent deployments.
Minimum Qualifications
- Bachelor’s degree, or 4+ additional years of cyber experience in lieu of a degree.
- 5+ years of experience in a cybersecurity role.
- Experience with Security Information and Event Management (SIEM) platforms and/or Splunk.
- Knowledge of Linux systems administration, general operating system security practices, TCP/IP networking, and network security concepts.
- Knowledge of Certification and Accreditation (C&A) processes.
- Knowledge of DoD policy and technical security guidance for information systems.
- DoD Directive 8570.1 IAT Level II or higher certification, or the ability to obtain within six (6) months.
- Splunk certification is required.
Preferred Qualifications
- Experience with Linux distributions, including Red Hat and CentOS.
- Experience with AWS or other cloud environments.
- Knowledge of ICS 500-27 audit collection requirements.
- Familiarity with Enterprise Security Services, Host Based Security Services, Enterprise Vulnerability Scanning Services, and User Activity Monitoring (UAM).
- Ability to modify feed creation to ingest customer logs in standardized formats to meet policy and compliance requirements.
Clearance Requirements
- An active TS/SCI with Polygraph is required.
Physical Requirements
- Must be able to remain in a stationary position 50% of the time.
- Occasionally moves about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers via email, phone, or virtual communication, which may involve delivering presentations
Similar jobs
- RS
Azure Infrastructure & Security Engineers
Reliable Software Resources
United States🇺🇸Remote1 week agoAdministrative - QS
Network Engineer with Security Clearance
NewQuantum Science Solutions
McLean, VA🇺🇸On-site23 hours agoTCP/IPAzureDNS+1Technology - IT
DevSecOps Security Engineer
NewInfosys Technologies Ltd
Richardson, TX🇺🇸Hybrid23 hours agoOWASPStakeholder ManagementTechnology - TI
Sr. Network Security Engineer:
NewThe Intersect Group
Cumming, GA🇺🇸Hybrid23 hours agoAWSOAuthSAML+8Technology - BS
COMPUTER NETWORK DEFENSE ANALYST Levels I-IV with Security Clearance
NewBTS Software Solutions
Annapolis Junction, MD🇺🇸$120k - $260k/yrHybridYesterday401kPenetration Testing - RT
Senior Information Systems Security Officer (ISSO) II - Tucson, with Security Clearance
RTX
Tucson, AZ🇺🇸$107.5k - $204.5k/yrOn-site7 weeks agoSplunkTechnology