Splunk Enterprise Security Engineer

1 month ago


Windsor Mill, United States Omm IT Solutions Full time
Job Description
Description of Work:

Our Federal Client is seeking a Splunk Enterprise Security Engineer who can develop custom detection content (correlation rules) identify threat activity. This includes developing notable events, visualizations, forms, reports, alerts, as well as Splunk Apps, Technology Add-ons, and normalize data sources to the Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The Splunk Engineer will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security app, spanning security, performance, and operational roles.

The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.

Duties and Responsibilities:

  • Alert use case development
  • Upgrade Splunk apps required by Splunk ES upgrades
  • Splunk Enterprise Security administration and management
  • Configure notable event actions, action menus and Adaptive Responses
  • Data onboarding and data ingestion normalization recommendations
  • Strong knowledge of security risk procedures, security patterns, authentication technologies and security attack pathologies
  • Develop, evaluate, and document, specific metrics for management purpose
  • Write complex code to install and manage the Splunk enterprise development
  • Performing maintenance and optimization of existing clustered Splunk deployments
  • Create Dashboards to monitor the traffic volumes, response times, errors, and warnings across various data centers
  • Monitor the web portals, log files and databases
  • Provide debugging and monitoring capabilities
  • Design and Develop Splunk for routine use
  • Solve complex Integration challenges and debug complex configuration issues
  • Consult with stakeholders to establish, maintain and refresh their strategic direction in cloud adoption
  • Become knowledgeable on the CDM technical requirements for the federal government's CDM program. Understand your role in CDM activities.
  • Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
  • Design, manage, and maintain enterprise SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
  • Maintenance, configuration and implementing products, appliances and devices on the enterprise network
Requirements

Basic Qualifications:

Minimum knowledge, skills, abilities needed.
  • Bachelor's degree and 7 years of experience, Master's degree and 5 years of experience, or 11 years of experience in lieu of a degree
  • At least 4 years' experience using customer-focused Splunk Enterprise Security SIEM engineering background - SME knowledge of ES v4.7
  • At least 4 years' experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments
  • At least 4 years of experience with:
    • In-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise
    • Direct experience with Splunk Engineering and data integration
    • Prior SIEM data modelling experience on similar platform at scale (>50 servers)
    • Scripting and development skills in Python/Perl with deep comprehension of regular expressions
    • Coordination and communication with other remotely deployed team members
    • Developing documentation with processes and procedures
    • Proposing, implementing automation features in a large enterprise environment
  • At least 3 years of experience with Linux and SQL/ODBC interfaces
  • At least 2 years of experience in app interface development, using REST API's
  • Hold active Splunk Core Certifications of at least Splunk Architect
  • Minimum of 3 year of experience in developing and tailoring reporting from network security tools.
  • Must be able to obtain and maintain a US Public Trust clearance
Preferred Qualifications:

Candidates with these skills will be given preferential consideration.
  • Experience with Splunk Common Information Model (CIM) and Enterprise Analytic
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision
  • Knowledge of Cloud Services such as AWS, Azure, Office365
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
  • Experience in automating Splunk Deployments and orchestration with in a Cloud environment


  • Milford Mill, United States Omm IT Solutions Full time

    Job DescriptionDescription of Work: Our Federal Client is seeking a Cyber Systems Engineer who will oversee the collection, storage and interpretation of cyber security data to enhance the Continuous Diagnostics and Mitigation (CDM) Program. Their duties will include sifting through data points to create organized categories, formatting data into other cyber...


  • Windsor Mill, United States System One Holdings, LLC Full time

    Job OverviewINFORMATION SECURITY SYSTEMS SPECIALISTSystem One Holdings, LLC is seeking qualified candidates for the role of Information Security Systems Specialist. This position is crucial in supporting the health and finance sector of a leading systems integrator. The specialist will be responsible for the aggregation, management, and analysis of...


  • Windsor Mill, United States Omm IT Solutions Full time

    Job Description Please Note: Selected candidate must reside within two (2) hours of the client's Headquarters in Woodlawn, MD Selected candidate must be willing to work on-site at least 2 days a week. Position Description: Provide engineering and operations support for the AWS CCaaS platform. Analyze application and platform and translate functional...


  • Milford Mill, United States Omm IT Solutions Full time

    Job DescriptionDescription of Work: Our Federal Client sector is seeking a Cyber Database Architect responsible for developing and implementing proper architecture and engineering safeguards around cyber security data. The architect is expected to have a deep knowledge of a broad range of information and physical security controls to protect data stores...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewPosition: RF Test EngineerCompany: Azure Summit TechnologySalary: CompetitiveAbout UsAzure Summit Technology is a well-established, expanding small enterprise with operations in multiple locations. We specialize in the development and delivery of high-performance RF hardware, firmware, and software solutions, alongside innovative multi-functional...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewPosition: RF Test EngineerCompany: Azure Summit TechnologyAbout Us:Azure Summit Technology is a well-established, expanding small enterprise with expertise in developing and delivering advanced RF hardware, firmware, and software solutions. Our focus is on creating innovative, multi-functional RF systems that meet the critical needs of national...


  • Windsor Mill, United States Omm IT Solutions Full time

    Job Description Please Note: Selected candidate must reside within two (2) hours of the client's Headquarters in Woodlawn, MD Selected candidate must be willing to work on-site at least 2 days a week. Position Description: Design, develop, and implement next-generation content management using system/software engineering best practices and the latest...


  • Windsor Mill, United States Omm IT Solutions Full time

    Job Description Please Note: Selected candidate must reside within two (2) hours of the client's Headquarters in Woodlawn, MD Selected candidate must be willing to work on-site at least 2 days a week. Position Description: Design, develop, and implement next-generation content management using system/software engineering best practices and the latest...


  • Windsor Mill, United States Evolver Federal Full time

    Job DescriptionJob DescriptionEvolver Federal is seeking a candidate to satisfy a request for an Information Security Officer for a program to support a government client. Responsibilities:The Information Security Officer will be responsible for:The assurance that all systems, components, and services, required by the client, are in compliance with federal...


  • Windsor Mill, United States System One Full time

    CYBER DATABASE ARCHITECT ALTA IT Services is seeking a Cyber Database Architect responsible for developing and implementing proper architecture and engineering safeguards around cyber security data. The architect is expected to have a deep knowledge of a broad range of information and physical security controls to protect data stores (potentially including...

  • Hardware Engineer

    1 week ago


    Windsor Mill, United States ManTech Full time

    Secure our Nation, Ignite your FutureBecome an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International Corporation, you'll help protect our national security while working on innovative projects that offer opportunities for advancement.Currently, ManTech is seeking a...


  • Windsor Mill, United States Omm IT Solutions Full time

    Job Description *** Selected candidate must reside within two (2) hours of Federal Headquarters in Woodlawn, MD *** Selected candidate must be willing to work on-site at least 2 days a week. Position Description: Lead the development of highly innovative products/solutions, achieved through collaboration and dialogue with other experts in the field. The...


  • Windsor Mill, United States System One Holdings, LLC Full time

    CYBER DATABASE ARCHITECT ALTA IT Services is seeking a Cyber Database Architect responsible for developing and implementing proper architecture and engineering safeguards around cyber security data. The architect is expected to have a deep knowledge of a broad range of information and physical security controls to protect data stores (potentially including...


  • Fort Mill, United States TEKsystems Full time

    Our client is seeking to add a Network Security Engineer to their Infrastructure and Operations department. This Engineer will possess technical expertise and engineering skill which allows her/him to be grow into a leading subject matter expert for both Investor and Advisor themed technology as well as enabling Cloud based solutions. This individual must be...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewSalary: CompetitiveAzure Summit Technology is a well-established, expanding small enterprise with operations that focus on the development and delivery of high-performance RF hardware, firmware, and software solutions. Our innovative, multi-functional RF systems are designed to meet the evolving needs of national defense clients across the...


  • Windsor Mill, United States Azure Summit Technology Full time

    About the RoleAzure Summit Technology is a leading provider of high-performance RF hardware, firmware, and software products, as well as innovative, practical, multi-function RF systems solutions that address emerging missions of national importance for customers across the Department of Defense.We are a diverse team of highly qualified RF systems engineers...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewPosition: RF Test EngineerCompany: Azure Summit TechnologyAbout Us:Azure Summit Technology is a well-established and expanding small enterprise located in multiple regions. We specialize in the development and delivery of advanced RF hardware, firmware, and software solutions, along with innovative multi-functional RF systems designed to meet...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewPosition: RF Electronics TechnicianCompany: Azure Summit TechnologyLocation: On-siteSalary: CompetitiveAbout UsAzure Summit Technology is a well-established, expanding small enterprise with a focus on developing and delivering high-performance RF hardware, firmware, and software solutions. Our innovative, multi-functional RF systems address...


  • Windsor Mill, United States Azure Summit Technology Full time

    Job OverviewPosition: RF Electronics TechnicianCompany: Azure Summit TechnologyLocation: On-siteSalary: CompetitiveAbout UsAzure Summit Technology is a well-established, expanding small enterprise with expertise in developing and delivering high-performance RF hardware, firmware, and software solutions. Our innovative multi-functional RF systems address...


  • Windsor Mill, United States Apptad Inc Full time

    Job OverviewPosition: Apptad - Senior .Net Software EngineerLocation: Hybrid Work EnvironmentDuration: Long-Term EngagementKey ResponsibilitiesUtilize extensive knowledge of .NET 8, C#, and Microsoft Visual Studio 2022+ to design and implement software solutions.Collaborate with cross-functional teams to create innovative user interfaces and web components,...