Splunk Engineer
Edwards Management Consultants, Inc.
Arlington, VA
Full Time
Mid Level
5+ years
Posted 1 month ago Expired
This job has expired
Looking for a job like Splunk Engineer in or near Arlington, VA? Upload your resume and we'll notify you when similar positions become available.
Upload Your ResumeAbout This Role
Implement and maintain Splunk solutions, create complex queries and dashboards, and analyze logs for attack techniques to enhance security and compliance for clients.
Requirements
- Active Secret security clearance
- 5-7 years experience in Computer Science, Information Technology, or a related field
- Experience in building Splunk Technology Add-ons and configuring field extractions
- Proficiency in SPL (Search Processing Language)
- Experience in designing, developing, testing, troubleshooting, deploying, and maintaining Splunk solutions, reporting, alerting, and dashboards
- Extensive knowledge of a tier Splunk installation: indexers, forwarders, search heads, clusters
- Experience analyzing system, network, and application logs for attack techniques at all stages of the cyber kill chain
- Strong analytical and critical thinking skills
- Strong problem-solving skills to investigate and resolve Splunk platform and data ingestion issues
- Knowledgeable in using scripting languages (e.g., Python)
- Detail-oriented with a strong commitment to documenting configurations, processes, and best practices
Qualifications
- Masters Degree or equivalent combination of education in Computer Science, Information Technology, or a related field
- 5 to 7 years of experience
Nice to Have
- Experience with more than one enterprise-scale EDR and SIEM tool
- Experience consuming and analyzing Cyber Threat Intelligence for actionable takeaways
- Familiarity with ServiceNow cloud offering and log ingestion to Splunk
Skills
Python
*
Splunk
*
ServiceNow
*
HIPAA
*
GDPR
*
SIEM
*
Cyber Threat Intelligence
*
FISMA
*
EDR
*
SOC 2
*
Computer Science
*
Information Technology
*
SPL
*
* Required skills
Certifications
CISSP
(Required)
GCFA
(Required)
CEH
(Required)
GIAC GREM
(Required)
GCTI
(Required)
GCFR
(Required)
Splunk Certified Cybersecurity Defense Analyst
(Required)
Splunk Enterprise Security Certified Admin
(Required)