Job OverviewWe are seeking a
Senior Splunk Security Engineer to join our team. You will provide comprehensive information assurance and security engineering support by analyzing complex threat intelligence and integrating specialized methodologies to resolve enterprise system vulnerabilities. Additionally, you will architect, administer, and develop customized threat-detection content within the Defense Logistics Agency's (DLA) Splunk Enterprise Log Management (ELM) environment to optimize data mining and empower incident response teams. You will be located in Richmond, VA. This position will require travel.
Responsibilities include, but are not limited to:- Security Engineering and Information Assurance (IA): You are responsible for driving the integration of electronic processes and methodologies to resolve comprehensive system and technology challenges tied to IA requirements. This includes providing end-to-end security engineering support across the entire system lifecycle-encompassing the planning, design, development, testing, demonstration, and integration of secure information systems. You will also apply rigorous analytical and systematic approaches to optimize workflow, organizational alignment, and project planning.
- Threat Intelligence and Incident Response Support: You will conduct deep-dive analyses of threat information synthesized from a diverse array of sources, including system logs, Intrusion Detection Systems (IDS), formal intelligence reports, and vendor telemetry. Leveraging this intelligence, you will provide actionable analysis and strategic recommendations that directly align with and support the operational mandates of Computer Emergency Response Team (CERT) Incident Handlers (IH) and site Information Assurance Managers (IAM).
- Splunk Infrastructure Administration and Architecture Maintenance: You will serve as a primary administrator for the DLA Splunk Enterprise Log Management (ELM) architecture and its associated backend database infrastructure. Duties require full lifecycle management of the platform, meaning you will research, plan, install, configure, troubleshoot, proactively maintain, and execute backups for all architectural components, alongside executing critical system upgrades and daily maintenance routines.
- SIEM Content Development and Advanced Data Analytics: You will utilize Splunk Enterprise Security (ES) as a Security Information and Event Management (SIEM) platform to develop specialized rules, customized reports, data monitors, active channels, and trend analyses. By designing and implementing customized dashboards and tailored use cases, you will successfully identify emerging threats, optimize data mining operations across the DLA, and efficiently elevate high-threat items to critical incident responders.
Required Qualifications:- A Linux+ or Splunk Administrator certification.
- A minimum of seven (7) years of relevant IT experience.
- Experience creating custom dashboards and reports in Splunk using threat
- data.
- Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).
- Highly proficient with Cyber Defense Infrastructure Support -AND- System Administration.
Preferred Qualifications:- A bachelor's degree in a relevant field of study.
- Relevant certification meeting DOD 8570/8140 IAT level III.
- Relevant certification meeting DOD 8570/8140 CND-IS.
Clearance Requirements:- Must be a U.S. citizen
- Must possess a DoD current Secret clearance.