Cybersecurity Engineer (Splunk)Salary Range:Clearance: Active Top Secret clearance
Location: Columbus, OH or Richmond, VA
Performs a variety of routine project tasks applied to specialized cybersecurity problems. Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to cybersecurity requirements. Analyzes information security requirements. Applies analytical and systematic approaches in the resolution of problems of workflow, organization, and planning. Provides security engineering support for planning, design, development, testing, demonstration, and integration of information systems.Analyzes threat information gathered from logs, Intrusion Detection Systems (IDS), intelligence reports, vendor sites, and a variety of other sources. Creates customized dashboards using the Security Information and Event Management (SIEM) tool Splunk ES to elevate high-threat items to incident responders. Administration knowledge of the Splunk ES and backend database infrastructure related to upgrades and daily maintenance is essential. Provide analysis and make recommendations in line with the roles of CERT Incident Handlers (IH) and site Information Assurance Managers (IAM). Develop ES rules, reports, dashboards, data monitors, active channels, trends, and use cases to identify threats and optimize data mining across DLA. Will research, plan, install, configure, troubleshoot, maintain, and back up all components in the DLA Splunk Enterprise Log Management (ELM) architecture.
Minimum Experience: - Seven (7) years of relevant IT experience
- Primary DCWF Work Role 521: Cyber Defense Infrastructure SupportProficiency Level: Intermediate (any of the following): Security+, CySA+, CEH, SSCP, GSEC, GMON, Cloud+, or PenTest+.
- Secondary DCWF Work Role 451: System Administrator Proficiency Level: Intermediate(any of the following): Security+, Cloud+, GSEC, GICSP, or SSCP.
- Computing Environment: Linux+, Splunk Administrator
- Experience creating custom dashboards and reports in Splunk using threat data.
- Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).
Why you will love working with us/ Perks- A comprehensive benefits package including healthcare (medical, dental, vision and disability)
- a 401k program where you are 100% vested from day one with an employer match after 90 days.
- an Educational Assistance program.
- a Student Loan Repayment Program
- Gym Reimbursement Program.
- Paid Time off
- Dynamics, passionate, multi-disciplinary team of creative minds to work with and many more.