Splunk Cyber Security Infrastructure / Cloud Platform SME (Hybrid)
Morrisville, NC, United States
Full Time Mid-level / Intermediate Clearance required USD 97K - 180K * est.
Tier One Technologies
Overview
- Tier One Technologies is urgently seeking a Splunk Cybersecurity Infrastructure Engineer with Cloud Platform Architect experience to support our direct US Government client.
- This hybrid contract-to-hire position can be located in Falls Church, VA, Morrisville, NC or Eagan, MN.
- SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT.
- Must be a US citizen.
Responsibilities
- Design, deploy, and maintain on-premises and cloud based Splunk environments to support enterprise-level monitoring, alerting, and reporting.
- Design, implement, configure and provide operational support in a hybrid on-prem Unix/Linux and cloud-based environment.
- Collaborate across DevOps, Security, and IT teams to optimize performance, ensure data integrity, system availability and support mission-critical operations.
- Off-hours and weekend efforts for systems maintenance, upgrades and support may be required from time to time.
Qualifications
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- 13+ years of Cybersecurity related experience.
- Proven hands-on experience with Splunk deployment and configuration management in large-scale environments.
- Expertise in Splunk Enterprise architecture, including indexers, search heads, deployment servers, and forwarders.
- Advanced knowledge of Unix/Linux systems administration and troubleshooting.
- Proficiency in writing complex Splunk queries, dashboards, and alerts using SPL (Search Processing Language).
- Strong scripting skills in Bash, Python, or Perl for automation and integration tasks.
- Experience with Splunk upgrades, patching, and performance tuning.
- Proficiency in integrating Splunk with cloud platforms (AWS, GCP, Azure).
- Understanding of security and compliance requirements and implementation of role-based access controls (RBAC) in Splunk.
- Experience with REST APIs for Splunk and external system integration.
- Strong knowledge of logging standards and best practices across application and infrastructure layers.
- Ability to analyze and troubleshoot complex data ingestion and parsing issues.
- CERTIFICATIONS: (One or more required):
- CompTIA Security +
- CPTE - Certified Penetration Testing Engineer
- CEH - Certified Ethical Hacker
- CISA - Certified Information Systems Auditor
- CISSP (CISSP-ISSEP or CISSP-ISSAP or CISSP-ISSMP)
- Strong understanding of network protocols, operating systems, applications, and device event telemetry.
- Familiarity with network defense tools (firewall, IPS/IDS, WAF/CDN, etc.), endpoint defense tools (EDR, anti-malware) a plus.
- Experience with SAAS- or cloud-hosted Splunk implementation a plus.
- Excellent interpersonal and organizational skills.
- Must be a US Citizen and able to obtain a Position of Public Trust Clearance.
- Must be able to pass a drug screening, criminal history, and credit checks.
- Must have lived in the United States for the past 5 years.
- Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members).
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Automation AWS Azure Bash CDN CEH CISA CISSP Clearance Cloud Compliance CompTIA Computer Science DevOps EDR Firewalls GCP IDS IPS Linux Malware Monitoring Pentesting Perl Python SaaS Scripting Splunk UNIX
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.