Overview/ Job Responsibilities Sev1Tech is seeking a talented Splunk Engineer/Operator to join our team to support a new customer on a highly-visible contract.
The Splunk Engineer/Operator will be a member of Network Operations and Security Center (NOSC) team uses Splunk for content development, analysis and will be expected to manage multiple assignments, changing priorities, and work independently with little oversight.
Responsibilities include but are not limited to: Build, implement, and administer Splunk in Windows and Linux environments Work with existing and custom Splunk applications and add-ons to fulfill customer needs Provide operations and maintenance support for a distributed Splunk environment consisting of heavy forwarders, indexers, and search head servers, spanning security, performance, and operational roles Editing and maintaining Splunk configuration files and apps Onboard data to Splunk via forwarder, scripted inputs, TCP/UDP, and modular inputs from a variety of sources Provider operational support for Splunk Universal Forwarder on Linux and Windows endpoints Manage, and support automation solutions for Splunk deployment and orchestration in on-premise and cloud environments Documentation, reporting, presentation, teamwork, and DHS wide collaboration are among the expected duties and mission of the task order Minimum Qualifications Bachelor's degree in Information Technology, Computer Science, or related degree Eight (8) to twelve (12) years of prior relevant experience in order to operate within the scope contemplated by the level; experience in lieu of degree Four (4) years of experience with Splunk in distributed deployments Excellent written and oral skills, ability to work closely with multiple customers, manage expectations and track engagement scope Experience with Splunk Enterprise Security or integration with other Security Information and Event Management (SIEM) platforms Proficient at data on-boarding activities including routing, parsing, and normalizing events to the Splunk Common Information Model (CIM) Proficiency on-boarding data using Splunk developed add-ons for Windows, Linux, and common third-party devices and applications Experience on-boarding data into Splunk via forwarder, scripted inputs, TCP/UDP, and modular inputs from a variety of sources Proficiency managing Splunk using the Splunk command-line interface Proficiency managing Splunk using configuration files Experience collaborating with separate engineering teams to configure data sources for Splunk integration Proficiency implementing and on-boarding data in Splunk DB Connect Experience with Splunk performing systems administration, including performing installation, configuration, monitoring system performance and availability, upgrades, and troubleshooting General networking and security troubleshooting (firewalls, routing, NAT, etc.)
Splunk implementation and troubleshooting experience Experience in managing, maintaining, and administering multi-site indexer cluster Proficiency developing log ingestion and aggregation strategies per Splunk best practices Perform integration activities to configure, connect, and pull data with 3rd party software APIs Proficient in regular expressions Ability to autonomously prioritize and successfully deliver across a portfolio of projects Certification Requirement: Current Splunk Enterprise Certified Admin certification Certification Requirement: At least one of the following certifications in CASP, GCIH, GCWN, GISF, GISP, GSSP, GICSP, GSSP, SEI, CISSP, CCSP, CSSLP, SSCP, CCNP, CCNP Security, CCIE Security, CEH, ECSP, MCSE, RHCA, RHCE, VCP, VCAP, VCIX, VCDX Able to provide proof of U.S.
Citizenship in order to obtain a Public Trust clearance About Sev1Tech LLC Founded in 2010, Sev1Tech provides IT, engineering, and program management solutions delivery.
Sev1Tech focuses on providing program and IT support services to critical missions across Federal and Commercial Clients.
Our Mission is to Build better companies.
Enable better government.
Protect our nation.
Build better humans across the country.
Join the Sev1Tech family where you can achieve great accomplishments while fostering a satisfying and rewarding career progression.
Please apply directly through the website at: https://www.sev1tech.com/careers/current-openings// joinSev1tech For any additional questions or to submit any referrals, please contact: eileen.mckenziesev1tech.com Sev1Tech is an Equal Opportunity and Affirmative Action Employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.