Security Information Event Manager (SIEM) Administrator

Castalia Systems

$120K — $124K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • High School Diploma required; Bachelor's in Computer Science is equivalent to 4 years of related experience.
  • At least 4 years of system/network administration or development experience, plus 2 years of Splunk administration.
  • Must meet Intermediate Proficiency Level qualifications per DoD 8140.03-M.
  • IAM-II Certification required; options include CISM, CISSP (or associate), GSLC, CCISO, CAP, CASP+ CE, HCISSP.
  • Splunk Enterprise Certified Admin credential is mandatory.
  • Experience with Linux server administration is essential.
  • Strong analytical skills and problem-solving abilities are required.

Responsibilities

  • Implement, install, and troubleshoot Splunk Enterprise and Splunk Enterprise Security systems.
  • Maintain and administer configurations, indexes, apps, and knowledge objects for SE and ES.
  • Monitor system health, capacity, and performance proactively.
  • Configure new data inputs to enhance data collection capabilities.
  • Create security dashboards, reports, alerts, and notifications for security monitoring.
  • Collaborate with administrators to enhance security monitoring capabilities.
  • Perform updates and patches on the Splunk platform and document configurations.

Benefits

  • Medical, dental, and vision coverage.
  • 401(k) matching program.
  • Generous paid time off (PTO) and holidays.
  • Professional training opportunities for growth.
  • Pet insurance for your furry friends.
Full Job Description
Job Type: Full-Time/Onsite

Clearance: Secret preferred

Must be a U.S. Citizen

Job Summary

A Security Information Event Manager (SIEM) Administrator is responsible for managing the organization's security information and event management (SIEM) system using Splunk. This role involves implementing, maintaining, troubleshooting, and optimizing the SIEM system to ensure effective security monitoring and incident response.

Roles and Responsibilities

A qualified candidate will perform the following duties and responsibilities, but are not limited to:
  • Implement, install, and troubleshoot Splunk Enterprise (SE) and Splunk Enterprise Security (ES) systems.
  • Maintain and administer SE and ES configurations, indexes, apps, and knowledge objects.
  • Monitor system health, capacity, and performance to proactively address issues.
  • Configure new data inputs to expand data collection capabilities.
  • Create security dashboards, reports, alerts, and notifications.
  • Collaborate with system administrators to enhance security monitoring capabilities.
  • Perform updates and patches on the Splunk platform.
  • Audit and review security practices to prevent security incidents.
  • Maintain documentation of system configurations and changes.

Required Qualifications
  • High School Diploma.
  • At least 4+ years of system, network administration, or developer experience and 2+ years of Splunk administration. A Bachelor's degree in Computer Science can be considered in lieu of the 4 years of system/network admin or developer experience.
  • IAW DoD 8140.03-M, must meet the Intermediate Proficiency Level qualifications.
  • IAM-II Certification (one or more of the following): CISM, CISSP (OR ASSOCIATE), GSLC, CCISO, CAP, CASP+ CE, HCISSP.
  • Must have Splunk Enterprise Certified Admin credential.
  • Must have experience administering Linux servers.
  • Must have experience with SIEM Content Development.
  • Demonstrated experience of strong analytical and problem-solving skills.
  • Excellent communication and collaboration skills.

Preferred Qualifications:
  • Red Hat Linux administrator certification.
  • Experience with Splunk Enterprise Security.
  • Experience in a virtualized environment.
  • One or more relevant CND certifications: CISSP, CASP+ CE, SSCP, CySA+, CEH, or GCIH.


Physical Requirements/Work Environment
  • Typical office environment.

Travel
  • Not required.

Compensation

At Castalia Systems, we provide you with opportunities and choices and support your total well-being. Our benefits include: Medical, dental, vision coverage, 401k matching, generous PTO, paid holidays, professional training opportunities, and even pet insurance to ensure your furry friends are cared for too. All regularly scheduled employees working at least 30 hours per week are eligible to participate in Castalia Systems• benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.

Salary at Castalia Systems is determined by various factors, including but not limited to location, position knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $120,000.00 to $124,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Castalia Systems• total compensation package for employees.

function load() { var urllocation = location.href; //find url parameter if(urllocation.indexOf("#") == -1 || urllocation.indexOf("#job") > -1){ window.location.hash="job"; } }

Similar Jobs

More Jobs at Castalia Systems

More Information Technology Jobs

Find similar Security Information Event Manager (SIEM) Administrator jobs: