Sr. Splunk Enterprise Security App Dev/Administrator

2 weeks ago


Seattle, United States ITmPowered, LLC Full time
Sr. Splunk Enterprise Security App Dev/Administrator (Remote) - ITmPowered

Sr. Splunk Enterprise Security Developer Administrator will develop, create, integrate, and administer a highly advanced Splunk Security application (eSAR) developed internally to detect improper access to protected data by employees and malicious user activity. Develop Splunk Apps and add-ons in support of Security Access cyber threat monitoring, threat management and data compliance across numerous business critical enterprise applications. Develop advanced Splunk ES Application functionality. Work with Splunk Developers using Agile development and administration using Agile project management methodologies. Work with the Splunk Engineering team, and support Splunk development, data integrations, and application administration using Agile methodologies. Splunk Enterprise Certified Architect OR Splunk Certified Developer required. Splunk Core Certified Consultant Preferred.

RESPONSIBILITIES:

  • Administering Splunk and Splunk App for Enterprise Security (ES) log management, ingestion, normalization.
  • Advanced Splunk analytics and the development and administration of custom Splunk applications.
  • Splunk data integrations with business-critical enterprise applications and systems.
  • Translating feedback from the business to Splunk technical requirement and solutions.
  • Develop specialized Splunk Security and Compliance applications, add-ons, data models, dashboards, content using Python, Splunk SPL, Splunk SimpleXML (OR JavaScript, CSS), Bash.
  • Develop custom Splunk applications and Add-Ons for inclusion of access events per use case criteria.
  • Leverage Modular design to onboard access/security logging applications and include in incident scoring.
  • Onboard access logging applications via modular design
  • Develop Splunk Risk scoring based on compliance conditions to determine suspicious access events.
  • Develop custom risk scoring to weed out white noise and only show actionable incidents to SOC Analysts.
  • Develop Dashboards for Security Analysts with detailed drill down capability for incident response.
  • Develop triage workflows for analysts to assign and track ongoing investigations.
  • Develop summary indexing enrichment of access events with IAM data, Application data, Break-the-Glass logs.
  • Aggregate access event data for specific criteria.
  • Enable fast searching across fully enriched access events over long periods of time.
  • Develop Break-the-Glass correlations in Splunk for contextual user access / app data mapping & monitoring.
Skills and experience:
  • Active Splunk Enterprise Certified Architect or Splunk Certified Developer - Required at a minimum.
  • Splunk Core Certified Consultant - strongly preferred.
Required Experience: In addition to active Splunk certification(s), must also have experience with the following:
  • Python development - Proficiency in Python programming language
  • Splunk SimpleXML or web development (JavaScript, CSS)
  • Splunk app & add-on development
  • Splunk data modeling
  • Strong experience in Splunk development, building dashboards, reports and lookup tables.
  • Programming experience (Python and Splunk SimpleXML OR JavaScript, CSS)
  • Working knowledge of Splunk including SPL, indexers, forwarders, search heads
  • Experience in OOAD, agile processes, design patterns
  • Expertise in large scale cyber security data analytics, identifying data-driven threat collection opportunities.
  • Prior Information security analysis experience in a Cyber Security Operations Center (CSOC)
Soft skills
  • Ability to collaborate with others, leveraging many project approaches (Agile/Scrum, Waterfall, Gantt Charts)
  • Comfortable working remotely with team members around the country. Self-starter with intellectual curiosity
LOGISTICS:
  • Work remotely anywhere in Domestic US. Preferred locations Colorado or Georgia.
  • Contract role through end of the year with potential for extension and/or conversion to perm.
  • COVID-19 Vaccine and Booster Required - OR must provide valid medical exemption from doctor in advance.
  • Must be able to successfully pass a 12-panel drug screen, 10-year background check, employment verification.
  • You will need to be a current US Citizen or valid Green Card holder. No need for visa now or in future. This role is not able to offer visa transfer or sponsorship now or in the future.
  • W2 only - No sub vendors. Sponsorship NOT available.
  • Must have direct contact information on resume (phone / email) to be considered.


  • Seattle, United States ITmPowered, LLC Full time

    Sr. Splunk Enterprise Security App Dev/Administrator (Remote) – ITmPowered Sr. Splunk Enterprise Security Developer Administrator will develop, create, integrate, and administer a highly advanced Splunk Security application (eSAR) developed internally to detect improper access to protected data by employees and malicious user activity. Develop Splunk Apps...

  • Splunk Consultant

    7 days ago


    Seattle, United States TEKsystems Full time

    Description: Our client is looking for a motivated engineer to become a core member of the Cyber Enablement team, specifically in Enterprise Security, guiding the enterprise organization to improve the practice of security observability. As a SIEM Engineer focused on Splunk ES for Cyber Enablement, you will work closely with the Tech Security and...

  • Sr. .Net Dev

    5 days ago


    Seattle, United States Georgia IT Inc Full time

    Sr. .Net Dev / Architect with Azure or AWS - must be willing to do 2-hour coding interview. Location - Seattle, WA - Remote - must be willing to work PST Duration - 6 months + USC & GC Preferred. No Third-party C2C available for this job Required Experience• Looking for 10+ years' experience.• 6+ years of experience advanced working as an SDE at an...


  • Seattle, United States Cash App Full time

    Job Description Job Description Company Description It all started with an idea at Block in 2013. Initially built to take the pain out of peer-to-peer payments, Cash App has gone from a simple product with a single purpose to a dynamic ecosystem, developing unique financial products, including Afterpay/Clearpay, to provide a better way to send, spend,...


  • Seattle, United States The AES Group Full time

    Title: Sr Azure DevOps engineer (DevOps, Kubernetes, Service Fabric, Python, Automation, Pipelines, and Scripting)Location: Hybrid (Seattle, WA) (Looking for locals or who can relocate)Duration: 12+ months (Extension possible)Job DescriptionAs a Sr Systems Engineer, you will partner with developers and software engineers to enable DevOps services and...

  • Sr Systems Engineer

    5 days ago


    Seattle, United States Saxon Global Full time

    Sr Systems Engineer Local (In the Office One Day a Week) 10 months, possible extension Top 3 must-have hard skills: 1 Scripting 5+ 2 Cloud 5+ 3 Security 5+ Disqualifiers?: •No App Dev developers! •Not willing to commute to the office Technology requirements?: •Scripting experience •Experience in security and focus on windows operating system...


  • Seattle, United States Cash App Full time

    Job DescriptionAbout Cash SecurityAt Cash, security is everyone’s responsibility, especially among engineering disciplines. Cash Security is a multidisciplinary team, closely aligned to the needs of the business. The team is composed of multiple engineering and governance teams, each specializing and collaboratively solving the security, privacy and...


  • Seattle, United States Cash App Full time

    Job DescriptionAbout Cash SecurityAt Cash, security is everyone’s responsibility, especially among engineering disciplines. Cash Security is a multidisciplinary team, closely aligned to the needs of the business. The team is composed of multiple engineering and governance teams, each specializing and collaboratively solving the security, privacy and...

  • Sr iOS Developer

    5 days ago


    Seattle, United States Saxon Global Full time

    As a Sr. Engineer - IoS consultant, you will be working on pioneering technology in the hardware and software world. You will be merging the hardware features with software to provide a unified, smooth customer experience over Bluetooth stack, location-based services while prioritizing privacy and security of customer data. Your will be interacting with...


  • Seattle, United States Saxon Global Full time

    As a Sr. Engineer - Android consultant, you will be working on pioneering technology in the hardware and software world. You will be merging the hardware features with software to provide a unified, smooth customer experience over Bluetooth stack, location-based services while prioritizing privacy and security of customer data. Your will be interacting with...

  • Oracle Apps FA

    3 weeks ago


    Seattle, United States Tata Consultancy Services Full time

    •This Role is Oracle APPS FA. Must have knowledge on O2C and P2P cycle and must have hands-on on all related oracle apps forms and should know the functionality of the forms. •Should have good insight into Oracle EBS Modules- Oracle Inventory, Oracle Order Management, Oracle Purchasing. •10+ Years of experience in working in oracle apps and should have...

  • Peoplesoft System

    3 weeks ago


    Seattle, United States ADPMN INC Full time

    Job DescriptionJob DescriptionRole:Peoplesoft System & Security AdministratorLocation: Seattle, Washington, 3 Days HybridDuration: 10 MonthsJob Description -This role will be responsible for supporting system administration and security functions within PeopleSoft.The role will primarily focus on production support to maintain the integrity of our existing...


  • Seattle, United States DevSelect Full time

    Title: Sr. Security Engineer/Architect Location:  Seattle Area Openings: 1 Type: Long-Term Contract Looking for a highly motivated, experienced Security Engineer/Developer/Architect. This individual needs to be highly technical and analytical with strong verbal and written communication skills with a deep understanding of Cloud Computing. Basic...

  • Oracle Apps FA

    2 weeks ago


    Seattle, United States Tata Consultancy Services Full time

    This Role is Oracle APPS FA. Must have knowledge on O2C and P2P cycle and must have hands-on on all related oracle apps forms and should know the functionality of the forms.•Should have good insight into Oracle EBS Modules- Oracle Inventory, Oracle Order Management, Oracle Purchasing.•10+ Years of experience in working in oracle apps and should have...


  • Seattle, United States ITmPowered, LLC Full time

    Sr. MMO Game Developer We are looking for Sr. Game Developers to engage in the development of MMO / MMORPG games, Server-side code, and backend applications / systems. Should have a passion for games as well as an understanding of both the front end and scalable back-end systems. Understanding and experience in MMO programming, server-side code underlying...


  • Seattle, United States ITmPowered, LLC Full time

    Sr. MMO Game Developer We are looking for Sr. Game Developers to engage in the development of MMO / MMORPG games, Server-side code, and backend applications / systems. Should have a passion for games as well as an understanding of both the front end and scalable back-end systems. Understanding and experience in MMO programming, server-side code underlying...


  • Seattle, United States Belcan Full time

    Software Dev Engineer II Job Number: 348668 Category: Software Programming / Dev Description: #NowHiring #SoftwareDevEngineer Job Title: Software Dev Engineer II Contract: 6 Months Belcan is a leading provider of professional IT, Engineering, Workforce Solutions and staffing in the United States, Canada, UK, Europe, and India. A Software Dev Engineer II Job...


  • Seattle, United States ITmPowered, LLC Full time

    Sr. ServiceNow Developer (VR/CC - SecOps) ServiceNow Development and Administration of Vulnerability Response (VR) and Configuration Compliance (CC) modules. Providing architectural, design, configuration/development and operational support for VR and CC. Prepare and conduct VR and CC and related dependencies updates. Provide ServiceNow functional and...

  • Sr PACS Analyst

    7 days ago


    Seattle, United States LanceSoft Full time

    We have an immediate need for a long-term Sr PACS Analyst with the following experience. This will be for contract UW 17-0050. Sr level PACS Imaging experience with any PACS vendor Sr level experience with systems administration and analysis Sr level experience with application/system configuration and implementation of radiology systems (and/or...


  • Seattle, United States ITmPowered, LLC Full time

    Sr. Web Platform Engineer - F5, NGINX Sr. Web Platform Engineer will work as a part of the enterprise digital platform delivery group with a strong focus on migrating Load Balancer Configurations from F5 BIG-IP LTM to NGINX Plus. Engineer, solution design, configuration, and troubleshooting of load balancing, caching, reverse proxy infrastructure on the...