Overview: Looking for a Splunk Service Engineer; Content Developer responsible for tuning and configuration of Splunk for Enterprise Security (ES) services, develop use cases with CISO end users to build content and assist in developing advanced security use cases.
Clearance Requirements: An Active Top Secret w/SCI eligibility is required. Candidates who do not meet this clearance requirement will not be considered for the position.
- Configure incident response and remediation workflows for ES.
- Develop and Implement Actionable Alerts and Workflow for Splunk as a CISO Monitoring tool
- Develop and Implement Apps & Knowledge Objects (KO) like Dashboard, Reports, Data Models
- Work with the Splunk Architect/Admin to promote private KO to Global KO
- Assist and/or train CISO Splunk Engineering team on Data Lifecycle Support
- Assist and/or train CISO Engineering team and analysts on Content Development
- Develop and implement automation and efficiencies with Splunk and CISO workflow
- Provide Analyst training and workshops on using Splunk
- Review new content, alerts and data sources with CISO Analysts.
- Bachelor's degree in Computer Science, Information Technology or related field.
- Minimum 2 years of experience working with Splunk and performing tasks described above.
- Thorough knowledge of data flow, client server and web-based systems, problem analysis and systems tuning; adept with network interfaces and technologies.
- 3-5 years of relevant experience in the cybersecurity domain.
- Strong communication skills in dealing with various stakeholders (technical and functional).