Splunk Engineer/Developer
Chandler, AZ, United States
Full Time Senior-level / Expert Clearance required USD 125K - 233K *
Sev1Tech
WE ARE SEV1TECH Serving critical missions for the United States at home and abroad Sev1Tech is a leading provider of IT modernization, cloud, cybersecurity, engineering, fielding, training, and program support services for U.S. government...Overview/ Job Responsibilities
Sev1Tech is seeking a talented Splunk Engineer/Operator to join our team to support a new customer on a highly-visible contract. The Splunk Engineer/Operator will be a member of Network Operations and Security Center (NOSC) team uses Splunk for content development, analysis and will be expected to manage multiple assignments, changing priorities, and work independently with little oversight.
Responsibilities include but are not limited to:
- Build, implement, and administer Splunk in Windows and Linux environments
- Work with existing and custom Splunk applications and add-ons to fulfill customer needs
- Provide operations and maintenance support for a distributed Splunk environment consisting of heavy forwarders, indexers, and search head servers, spanning security, performance, and operational roles
- Editing and maintaining Splunk configuration files and apps
- Onboard data to Splunk via forwarder, scripted inputs, TCP/UDP, and modular inputs from a variety of sources
- Provider operational support for Splunk Universal Forwarder on Linux and Windows endpoints
- Manage, and support automation solutions for Splunk deployment and orchestration in on-premise and cloud environments
- Documentation, reporting, presentation, teamwork, and DHS wide collaboration are among the expected duties and mission of the task order
Minimum Qualifications
Bachelor's degree in Information Technology, Computer Science, or related degree
- Eight (8) to twelve (12) years of prior relevant experience in order to operate within the scope contemplated by the level; experience in lieu of degree
- Four (4) years of experience with Splunk in distributed deployments
- Excellent written and oral skills, ability to work closely with multiple customers, manage expectations and track engagement scope
- Experience with Splunk Enterprise Security or integration with other Security Information and Event Management (SIEM) platforms
- Proficient at data on-boarding activities including routing, parsing, and normalizing events to the Splunk Common Information Model (CIM)
- Proficiency on-boarding data using Splunk developed add-ons for Windows, Linux, and common third-party devices and applications
- Experience on-boarding data into Splunk via forwarder, scripted inputs, TCP/UDP, and modular inputs from a variety of sources
- Proficiency managing Splunk using the Splunk command-line interface
- Proficiency managing Splunk using configuration files
- Experience collaborating with separate engineering teams to configure data sources for Splunk integration
- Proficiency implementing and on-boarding data in Splunk DB Connect
- Experience with Splunk performing systems administration, including performing installation, configuration, monitoring system performance and availability, upgrades, and troubleshooting
- General networking and security troubleshooting (firewalls, routing, NAT, etc.)
- Splunk implementation and troubleshooting experience
- Experience in managing, maintaining, and administering multi-site indexer cluster
- Proficiency developing log ingestion and aggregation strategies per Splunk best practices
- Perform integration activities to configure, connect, and pull data with 3rd party software APIs
- Proficient in regular expressions
- Ability to autonomously prioritize and successfully deliver across a portfolio of projects
- Certification Requirement: Current Splunk Enterprise Certified Admin certification
- Certification Requirement: At least one of the following certifications in CASP, GCIH, GCWN, GISF, GISP, GSSP, GICSP, GSSP, SEI, CISSP, CCSP, CSSLP, SSCP, CCNP, CCNP Security, CCIE Security, CEH, ECSP, MCSE, RHCA, RHCE, VCP, VCAP, VCIX, VCDX
- Able to provide proof of U.S. Citizenship in order to obtain a Public Trust clearance
About Sev1Tech LLC
Founded in 2010, Sev1Tech provides IT, engineering, and program management solutions delivery. Sev1Tech focuses on providing program and IT support services to critical missions across Federal and Commercial Clients. Our Mission is to Build better companies. Enable better government. Protect our nation. Build better humans across the country.
Join the Sev1Tech family where you can achieve great accomplishments while fostering a satisfying and rewarding career progression. Please apply directly through the website at: https://www.sev1tech.com/careers/current-openings/#/ #joinSev1tech
For any additional questions or to submit any referrals, please contact: eileen.mckenzie@sev1tech.com
Sev1Tech is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Automation CASP+ CCIE CCNP CCSP CEH CISSP Clearance Cloud Computer Science CSSLP Firewalls GCIH GICSP Linux Monitoring NetOps SIEM Splunk SSCP Windows
Perks/benefits: Career development Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.