SIEM Engineer/Splunk Certified Admin
2 days ago
Location: Annapolis Jct, MD
Category: SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin
Travel Required: No
Remote Type: No
Clearance: TS/SCI w/ Polygraph
Job Summary / Primary Responsibilities
The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong skills in system administration, log management, event correlation, and threat detection and will support building and maintaining a system that analyzes collected data and derives facts, inferences, and projections to determine if the systems being monitored are operating normally. The individual will work on a team responsible for configuring the systems which support analysts and end-users. The successful candidate will support the collection and extraction of data used to refine existing and new reports, analytics, and dashboards, and will be involved with the drafting and creation of reports and dashboards based on end-user requirements. She/he will also support the integration of resources across teams to better define the audit data being collected to eliminate false positives and false negatives from the data.
Basic/Required Qualifications
- At least 8 years of related experience.
- At least 2 years of experience with one or more of the following: StealthWatch, TripWire, Zenoss, ArcSight, Splunk.
- Experience in design, implementation, and support of Splunk core components, including: indexers, forwarders, search heads, and cluster managers.
- Experience with configuration and administration of Splunk ingestion and forwarding for new and existing applications and data.
- Experience with troubleshooting Splunk dataflow issues between the various Splunk core components.
- Experience configuring and deploying data collection for a variety of operating systems and networking platforms.
- Experience creating Dashboards and Analytics within SIEM tools.
- Experience working with monitoring systems supporting auditing, incident response, and system health.
- Understanding of networking components and devices, ports, protocols, and basic networking troubleshooting steps.
- The ability to troubleshoot issues with log feeds, search time, and field extractions.
- The ability to troubleshoot problems related to data solutions.
- Bachelor's Degree in Computer Science, Engineering, Information Assurance, or a related discipline.
- Network Security Operations Center (SOC) experience.
- Experience and talent in data visualization.
- Experience creating workflows for Incident Response within a SIEM Tool.
- Security+ Certification.
- GIAC Certified Incident Handler Certification.
- GIAC Cyber Threat Intelligence Certification.
- Cybersecurity certifications.
- Formal SIEM training.
- Experience working on an Agile team/program.
-
SIEM Engineer/Splunk Certified Administrator, Senior
6 months ago
Annapolis, United States Navstar Full timeWould you like to perform rewarding work while contributing to the success of an established, growing company? Navstar is an award-winning organization that has a proven track record of successfully providing IT services and solutions both as a prime and sub-contractor on mission focused IT programs. Our employees are integral players in support of...
-
SPLUNK Administrator
2 weeks ago
Annapolis Junction, United States ESC, Inc. Full timeSeeking a SPLUNK Administrator for a brand new program with the following locations available: 3 Site Locations: Annapolis Junction, MD Primary - JBAB Secondary - Landover, MD Third Position requires a current/active TS/SCI clearance. Summary: The Splunk Administrator will be responsible for managing and maintaining Splunk deployments....
-
Mid/Senior SIEM Engineer
4 weeks ago
Annapolis Junction, United States Belay Technologies Full timeBelay Technologies has been voted Baltimore Business Journal's (BBJ) Best Places to Wor k 2019, runner up in 2020 and a finalist in 2021! Belay Technologies is seeking a Mid-level or Senior Security Information and Event Management (SIEM) of all levels. The SIEM Architect will be responsible for collecting, parsing, and correlating events for a critical...
-
Splunk Engineer
2 weeks ago
Annapolis Junction, United States ELEVI Associates Full timeJob DescriptionJob DescriptionTo be able to Join the ELEVI you will need- You must be willing to work in the Annapolis Junction, MD area. You must have a current or active security clearance with a polygraph.Over the last 19+ years, you have gained demonstrated experience in planning and leading Systems Engineering efforts.Bachelor's degree in...
-
Sr Splunk Engineer
5 months ago
Annapolis Junction, United States NiSUS Technologies Corporation Full timeEnsure the Splunk infrastructure functions properly with PKI-based authentication, corporate authorization services, firewalls, and SSL/TLS communications. Contribute to development and ongoing improvement of industry best practices and standards for maintaining data analytics enterprise technologies. Assist with installing, testing, and deploying...
-
System Engineer 2
6 months ago
Annapolis Junction, United States Orion Consortium Full timePosition Description: Ensure the Splunk infrastructure functions properly with PKI-based authentication, corporate authorization services, firewalls, and SSL/TLS communications. Contribute to development and ongoing improvement of industry best practices and standards for maintaining data analytics enterprise technologies. Assist with installing,...
-
Mid Level Splunk Engineer
4 months ago
Annapolis Junction, United States NiSUS Technologies Corporation Full timeEnsure the Splunk infrastructure functions properly with PKI-based authentication, corporate authorization services, firewalls, and SSL/TLS communications. Contribute to development and ongoing improvement of industry best practices and standards for maintaining data analytics enterprise technologies. Assist with installing, testing, and deploying...
-
Security Operations Center
6 months ago
Annapolis Junction, United States EverWatch Full timeOverview EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our country’s most critical missions. We are a full-service government solutions company. Harnessing the most advanced technology and solutions, we strengthen defenses and control environments to preserve continuity and ensure...
-
System Engineer 2
6 months ago
Annapolis, United States Orion Consortium Full timePosition Description: Ensure the Splunk infrastructure functions properly with PKI-based authentication, corporate authorization services, firewalls, and SSL/TLS communications. Contribute to development and ongoing improvement of industry best practices and standards for maintaining data analytics enterprise technologies. Assist with installing, testing,...
-
Automation Security Engineer
3 weeks ago
Annapolis Junction, United States Maximus Full timeGeneral information ...
-
Automation Security Engineer
3 weeks ago
Annapolis Junction, United States Maximus Full timeGeneral information ...
-
Automation Security Engineer
5 days ago
Annapolis Junction, United States Maximus Full timeGeneral information Job Posting Title Automation Security Engineer Date Monday, September 23, 2024 City Annapolis Junction State MD Country United States Working time Full-time Description & Requirements Maximus is seeking a proficient Automation Security Engineer to provide advanced expertise in securing automated systems for a federal client's critical...
-
Automation Security Engineer
5 days ago
Annapolis Junction, United States Maximus Full timeGeneral information Job Posting Title Automation Security Engineer Date Monday, September 23, 2024 City Annapolis Junction State MD Country United States Working time Full-time Description & Requirements Maximus is seeking a proficient Automation Security Engineer to provide advanced expertise in securing automated systems for a federal client's critical...
-
Automation Security Engineer
4 days ago
Annapolis Junction, United States Maximus Full timeGeneral information Job Posting Title Automation Security Engineer Date Monday, September 23, 2024 City Annapolis Junction State MD Country United States Working time Full-time Description & Requirements Maximus is seeking a proficient Automation Security Engineer to provide advanced expertise in securing automated systems for a federal client's critical...
-
Automation Security Engineer
2 weeks ago
Annapolis Junction, United States Maximus Full timeGeneral information ...
-
Sr. Database Admin
2 weeks ago
annapolis junction, United States JASINT Full timeJob Title: Sr. Database Admin / Engineer - ExadataLocation(s): Annapolis Junction, MD Hours: Regular Full-TimeSalary Range: $115k/yr - $175k/yrClearance Requirements:This position requires a current and active TS/SCI FSP clearance at the time of application.What you will be doing:Sr. Oracle Database Administrator with 10+ years Oracle database administration...
-
Trellix ePO System Admin
4 weeks ago
Annapolis Junction, United States ITCNP Full timeJob DescriptionJob DescriptionTrellix ePO System AdminThis position involves installing and configuring required Trellix products, including but not limited to Trellix Endpoint Security (ENS) Client, ENS Firewall, Threat Prevention, Access Protection on enterprise Microsoft and Linux endpoints; maintaining malware security compliance and...
-
DevSecOps Engineer
3 weeks ago
Annapolis Junction, United States Maximus Full timeGeneral information ...
-
DevSecOps Engineer
3 weeks ago
Annapolis Junction, United States Maximus Full timeGeneral information ...
-
System Engineer 2
1 month ago
Annapolis Junction, United States Gormat Full timeJob Description: Performs a variety of complex project tasks applied to specialized technology problems. Tasks involve integration of electronic processes or methodologies to resolve total system problems or technology problems. Applies analytical and systematic approaches in the resolution of problems of work flow, organization, and planning. Directs and...