SIEM/Splunk Engineer

6 days ago


Washington, United States Coalfire Federal Full time
About Coalfire

Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including Amazon, Microsoft, IBM, Google and Oracle and Federal agencies. Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer place by solving our clients' toughest security challenges.

But that's not who we are - that's just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

We're currently seeking a SIEM/Splunk Engineer to support our Federal team in Washington, D.C. (Hybrid; 3 days on site).

What you'll do

  • Development, deployment, or administration of Splunk.
  • Onboard Splunk ES critical data sources - ingestion of critical data sources/data logs from the enterprise into the Security Information Event Management (SIEM) tool to meet the Splunk Enterprise Security (ES) implementation.
  • Normalize Log Data to Common Information Model (CIM) as required by Splunk ES to meet the provided security use cases (Rules/Alerts).
  • Create viewable Splunk dashboards to provide visibility into ingested log data.
  • Create alerts that trigger/activate on configured setting to deploy or sends a note, email, or attachments to a particulate destination email or groups.
  • Create security rules (alerts) that trigger on anomalous activities or threat detections.
  • Splunk Support - Assisting Customers with any issues when ingestion of logs that are not working properly or communication issues with Splunk.
  • Resolve Splunk infrastructure or system issues.
  • Development, deployment, or administration of VMware, RSA NetWitness, Cisco StealthWatch or similar tools.
  • Check virtual server availability, functionality, integrity, and efficiency.
  • Manage virtual server resources including performance, capacity, availability, serviceability, and recoverability.
  • Monitor and maintain virtual server configuration.
  • Diagnose failed servers or connectivity problems.
What you'll bring
  • Experience working with cloud services such as AWS, Azure and O365 and cloud access security brokers.
  • Experience in the use of network monitoring tools with a strong understanding of network protocols.
  • Ability to perform security analysis, development and implementation of security policies, standards, and guidelines.
  • Ability to quickly explore, examine and understand complex security problems and how it affects a customer's business.
  • Experience with both the Linux and Windows operating systems.

Education
Completed Bachelor's degree from an accredited university is required, preferably in an IT related field.

Clearance / Suitability

Ability to obtain a clearance or a Public Trust is preferred, however all clearance levels and non-cleared applicants will also be considered.

Certifications

Our aim is to build a technologically diverse team - so while we don't have a set list, there may be certain benchmarks we look for that apply to your expertise. We recommend checking out the DoD Approved 8570 Baseline Certifications as an example.

Preferred certifications typical for roles in our federal delivery services may include: Security+, CEH, CISA, CISSP, CISM, or other industry recognized certification.

Years of Experience

At least 5 to 7 years of hands-on experience with security monitoring tools such as IDS/IPS, FWs and NACs and protocols such as NetFlow (Snort, Bro, Palo Alto, Checkpoint, Cisco ISE, FireEye, Gigamon).

Why you'll want to join us

Our people make Coalfire Federal great. We work together on interesting things and achieve exceptional results. We act as trusted advisors to our customers and are committed to client-focused innovation as well as innovation in the industries that we serve.

Coalfire offers our people the chance to grow professionally with colleagues they like and respect while tackling challenges that stretch their minds and expand their skill sets. Regardless of location, you'll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You'll have opportunities to join employee resource groups, participate in in-person and virtual events, and more.

You'll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support memberships, and comprehensive insurance options.

Coalfire is an EEO employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

  • Washington, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a Senior SIEM Support Engineer (Splunk) with an active Secret clearance to support our DOI customer's Security Operation Center in DC or Reston Virginia. Master's degree (MA/MS) RequiredMinimum 10 years of experienceSenior level, support for Information Security (INFOSEC) and trusted systems technology.Assists in the...

  • SIEM/Splunk Engineer

    3 weeks ago


    Washington, United States Coalfire Federal Full time

    About Coalfire Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships...

  • SIEM/Splunk Engineer

    2 weeks ago


    Washington, United States Coalfire Federal Full time

    About Coalfire Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships...


  • Washington, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a SIEM Support Splunk Architect with an active Secret clearance to support our DOI customer's Security Operation Center in DC or Reston Virginia. Bachelor's degree required. Minimum 12 years of experience. Provides technical direction and expertise in a variety of specialized areas including information systems...


  • Washington, United States Node.Digital Full time

    Security Splunk Architect/Engineer Location: Washington DC metro area (Hybrid) Must have an active Secret OR Top Secret Clearance We are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate's primary responsibility is to maintain and enhance the existing Splunk...


  • Washington, United States Node.Digital Full time

    Job DescriptionJob DescriptionSecurity Splunk Architect/EngineerLocation: Washington DC metro area (Hybrid)Must have an active Secret OR Top Secret ClearanceWe are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate's primary responsibility is to maintain and enhance...


  • Washington, United States Node.Digital Full time

    Security Splunk Architect/Engineer Location: Washington DC metro area (Hybrid) Must have an active Secret OR Top Secret Clearance We are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate's primary responsibility is to maintain and enhance the existing Splunk...


  • Washington, United States Node.Digital LLC Full time

    Location: Washington DC metro area (Hybrid)Must have an active Secret OR Top Secret ClearanceWe are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate's primary responsibility is to maintain and enhance the existing Splunk infrastructure in the enterprise. Further...

  • Splunk Engineer

    3 weeks ago


    Washington, United States Nyla Technology Solutions Full time

    Job DescriptionWe are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate’s primary responsibility is to maintain and enhance the existing Splunk infrastructure in the enterprise. Further projects will involve the implementation of Splunk Enterprise Security (ES) and...

  • Splunk Engineer

    2 weeks ago


    Washington, United States Nyla Technology Solutions Full time

    Job DescriptionWe are seeking a Security Splunk Architect/Engineer to support a Navy enterprise network within the Engineering and Cyber Divisions. The candidate’s primary responsibility is to maintain and enhance the existing Splunk infrastructure in the enterprise. Further projects will involve the implementation of Splunk Enterprise Security (ES) and...

  • Splunk Engineer

    4 weeks ago


    Washington, United States Computer World Services (CWS)Corporation Full time

    Job Description The Splunk Engineer will be responsible for the entire end to end deployment of the Splunk family of software to support OFR's log retention, aggregation and analysis requirements. It is required that the candidate be well versed in Splunk technology and implementation of best practices and have a working knowledge in the variety of...


  • Washington, United States Ark Solutions Full time

    Role: Security Engineer/ Splunk Engineer Washington, DC (Onsite) 4-6 months Contract Education: Bachelor's degree in in Cybersecurity or related field. Required Skills: "Five (5) to seven (7) years of hands-on experience with security monitoring tools such as IDS/IPS, FWs and NACs and protocols such as NetFlow (Snort, Bro, Palo Alto, Checkpoint, Cisco...


  • Washington, United States Ark Solutions Full time

    Role: Security Engineer/ Splunk Engineer Washington, DC (Onsite) 4-6 months Contract Education: Bachelor's degree in in Cybersecurity or related field. Required Skills: "Five (5) to seven (7) years of hands-on experience with security monitoring tools such as IDS/IPS, FWs and NACs and protocols such as NetFlow (Snort, Bro, Palo Alto, Checkpoint, Cisco...


  • Washington, United States Ark Solutions Full time

    Role: Security Engineer/ Splunk Engineer Washington, DC (Onsite) 4-6 months Contract Education: Bachelor's degree in in Cybersecurity or related field. Required Skills: "Five (5) to seven (7) years of hands-on experience with security monitoring tools such as IDS/IPS, FWs and NACs and protocols such as NetFlow (Snort, Bro, Palo Alto, Checkpoint, Cisco...

  • DHS HSEN

    3 weeks ago


    Washington, United States Versar Full time

    Job Description Job Description Position Summary BayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a...


  • Washington, United States Computer World Services Corp Full time

    Job Details Job Description The Splunk Engineer will be responsible for the entire end to end deployment of the Splunk family of software to support OFR's log retention, aggregation and analysis requirements. It is required that the candidate be well versed in Splunk technology and implementation of best practices and have a working knowledge in the variety...

  • DHS HSEN

    4 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a...

  • DHS HSEN

    2 months ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a...

  • DHS HSEN

    2 weeks ago


    Washington, United States Versar, Inc. Full time

    Job DescriptionJob DescriptionPosition SummaryBayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a...


  • Washington, United States Versar Global Solutions Full time

    Position Summary BayFirst Solutions, a subsidiary of Versar, Inc., is seeking a Security Architect (SIEM & SOAR) to support the DHS’ Homeland Security Enterprise Network (HSEN) within the Office of the Chief Information Officer (OCIO), IT Operations, Enterprise Engineering Division (EED). This resource will be a member of a high functioning team of network...