Back to search
BOAB Ventures Linkedin · Posted 21d ago

Cybersecurity Engineer 4 - SIEM / SPLUNK Engineer with Security Clearance

Columbus

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Job Description

Performs a variety of routine project tasks applied to specialized information assurance problems. Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to IA requirements. Analyzes information security requirements. Applies analytical and systematic approaches in the resolution of problems of workflow, organization, and planning. Provides security engineering support for planning, design, development, testing, demonstration, integration of information systems. Analyzes threat information gathered from logs, Intrusion Detection Systems (IDS), intelligence reports, vendor sites, and a variety of other sources. Creates customized dashboards using Security Information and Event Management (SIEM) tool Splunk ES to elevate high threat items to incident responders. Administration knowledge of the Splunk ES and backend database infrastructure related to upgrades and daily maintenance is essential. Provide analysis and make recommendations in line with the roles of CERT Incident Handlers (IH) and site Information Assurance Managers (IAM). Develop ES rules, reports, dashboards, data monitors, active channels, trends and use cases to identify threats and optimize data mining across DLA. Will research, plan, install, configure, troubleshoot, maintain and backup all components in the DLA Splunk Enterprise Log Management (ELM) architecture. Required Qualifications

  • Seven (7) years of relevant IT experience
  • DOD Secret Clearance
  • Must be eligible for IT I
  • Relevant certification meeting DOD 8570/8140 IAT level III; candidate must possess one of the following certifications: CASP+ CE, CCNP Security, CISA, CISSP, GCED, GCIH CCSP
  • Relevant certification meeting DOD 8570/8140 CND-IS; candidate must possess one of the following certifications: CND, GICSP, GCED, CySA+ or Security+
  • Computing Environment: Linux+, Splunk Administrator
  • Experience creating custom dashboards and reports in Splunk using threat data.
  • Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search