Security Information Event Manager (SIEM) Administrator

Castalia Systems

$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Splunk Enterprise Certified Admin credential required.
  • Experience in administering Linux servers is essential.
  • Familiarity with SIEM Content Development is a must.
  • Strong analytical and problem-solving skills demonstrated.
  • Excellent communication and collaboration abilities.

Responsibilities

  • Implement and troubleshoot Splunk Enterprise and Splunk Enterprise Security systems.
  • Maintain configurations, indexes, apps, and knowledge objects within Splunk.
  • Monitor system health and proactively address performance issues.
  • Configure new data inputs to enhance data collection.
  • Create security dashboards, reports, alerts, and notifications.
  • Collaborate with system administrators to improve security monitoring.
  • Conduct updates and patches on the Splunk platform.

Benefits

  • Medical, dental, and vision coverage.
  • 401k matching.
  • Generous paid time off (PTO).
  • Paid holidays.
  • Professional training opportunities.
  • Pet insurance available.
Full Job Description
Job Type: Full-Time

Clearance: Secret

Must be a U.S. Citizen

Benefits: Medical, dental, and vision coverage, 401k matching, generous PTO, paid holidays, professional training opportunities, and even pet insurance to ensure your furry friends are cared for too.

Job Summary

A Security Information Event Manager (SIEM) Administrator is responsible for managing the organization's security information and event management (SIEM) system using Splunk. This role involves implementing, maintaining, troubleshooting, and optimizing the SIEM system to ensure effective security monitoring and incident response.

Roles and Responsibilities

A qualified candidate will perform the following duties and responsibilities, but are not limited to:
  • Implement, install, and troubleshoot Splunk Enterprise (SE) and Splunk Enterprise Security (ES) systems.
  • Maintain and administer SE and ES configurations, indexes, apps, and knowledge objects.
  • Monitor system health, capacity, and performance to proactively address issues.
  • Configure new data inputs to expand data collection capabilities.
  • Create security dashboards, reports, alerts, and notifications.
  • Collaborate with system administrators to enhance security monitoring capabilities.
  • Perform updates and patches on the Splunk platform.
  • Audit and review security practices to prevent security incidents.
  • Maintain documentation of system configurations and changes.

Knowledge and Skills
  • Must have Splunk Enterprise Certified Admin credential.
  • Must have experience administering Linux servers.
  • Must have experience with SIEM Content Development.
  • Demonstrated experience of strong analytical and problem-solving skills.
  • Excellent communication and collaboration skills.

Education
  • High School Diploma.
  • At least 4+ years of system, network administration, or developer experience and 2+ years of Splunk administration.
  • IAW DoD 8140.03-M, must meet the Intermediate Proficiency Level qualifications.
  • IAM-II Certification (one or more of the following): CISM, CISSP (OR ASSOCIATE), GSLC, CCISO, CAP, CASP+ CE, HCISSP.

Preferred Qualifications:
  • Red Hat Linux administrator certification.
  • Experience with Splunk Enterprise Security.
  • Experience in a virtualized environment.
  • One or more relevant CND certifications: CISSP, CASP, OSCP, CySA+, CEH, or GCIH.


Physical Requirements/Work Environment
  • Typical office environment.

Travel
  • Not required.

Company Description

Castalia Systems is a proven business partner providing mission critical solutions to the Federal Government. We provide cutting edge solutions from Securing and Managing Data to Systems Engineering and Development. Castalia Systems is a pioneer in Artificial Intelligence Design and Application.

With our vast knowledge of our customers needs and relevant technology, our team is able to bring successful solutions to every mission. We are one-upping our competitors by providing premium IT solutions and platforms with a cutting edge technology so it's so evident when you compare us with anyone.

Disclaimer

Castalia Systems is an equal employment opportunity and affirmative action employer and strives to comply with all applicable laws prohibiting discrimination based on race, color, creed, sex, sexual orientation, age, national origin, or ancestry, physical or mental disability, veteran status, marital status, HIV-positive status, as well as any other category protected by federal, state, or local laws. All such discrimination is unlawful, and all persons involved in the operations of the company are prohibited from engaging in this type of conduct.

#CJ

Similar Jobs

More Jobs at Castalia Systems

More Information Technology Jobs

Find similar Security Information Event Manager (SIEM) Administrator jobs: