Senior Splunk Engineer

Posted 2hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Splunk Engineer engineering and optimizing SIEM infrastructure for CNI, a federal and commercial technology services company. Managing enterprise Splunk deployments, Linux servers, integrations, alerts, dashboards, and security operations.

Responsibilities:

  • Engineer, develop, deploy, integrate, optimize, and maintain the Splunk SIEM infrastructure and related applications, integrations, apps, and interfaces
  • Deploy Splunk products, apps, reports, alerts, and dashboards using SDLC methodologies and business best practices
  • Increase infrastructure efficiency to connect additional enterprise data sources to Splunk Enterprise
  • Develop change-management plans and lead prototyping and testing of new features and solutions
  • Manage and monitor Linux-based on-premises server infrastructure, including configuration and software upgrades
  • Develop, maintain, and optimize internal and external SIEM components
  • Oversee the optimization, operation, and health of Splunk components and data-source connections
  • Provide technical consulting, advanced technical design, specifications, and planning assistance
  • Mentor Tier II technicians and lead technical discussions regarding SIEM and SIEM data connections
  • Share knowledge with junior security architects and engineers and recommend training
  • Apply industry best practices and innovative ideas to continuously improve the Splunk environment
  • Support the federal client and provide troubleshooting, documentation, system remediation, and operational recommendations

Requirements:

  • Bachelor's degree in Computer Science, Management of Information Systems, Cybersecurity, or a related Math or Science discipline
  • Minimum six (6) years in IT infrastructure, networking, architecture, administration, or security
  • Six (6) years of Splunk expertise, including at least three (3) years with large-scale enterprise-level solutions
  • Certified Splunk Architect certification required
  • Ability to obtain, maintain, and access classified information at the Public Trust level
  • Senior-level mastery of SIEM front-end and back-end operations and configurations
  • Extensive knowledge of Splunk Enterprise Security and CIM compliance
  • Extensive knowledge of Splunk Risk Based Alerting (RBA)
  • Understanding of data flows and interconnections between multiple systems within network environments
  • Extensive knowledge of Linux-focused system back-end engineering and administration
  • Extensive experience with SIEM systems and security event correlation
  • Experience with Splunk premium apps, including Enterprise Security
  • Experience architecting, developing, deploying, and configuring customized technical add-ons
  • Ability to operate autonomously with minimal supervision and provide accurate, precise documentation
  • Excellent troubleshooting, written, verbal, and communication skills
  • Perl, Linux shell scripting, and Regex experience highly preferable
  • Additional Splunk certifications, CEH, CySA+, GSEC, CISM, CCNA, Security+, Server+, Linux+, or Cloud+ are preferred

Benefits:

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Company life insurance
  • Short-Term and Long-Term Disability Insurance
  • 401(k) with immediate vesting
  • Professional Development Assistance
  • Legal Aid Assistance Program
  • Family Planning / Fertility Assistance
  • Personal Time Off (PTO)
  • Observance of Federal Holidays
  • Employee Assistance Program (EAP)
  • Training and Development Opportunities