Posted today
Top Secret/SCI
Unspecified
Polygraph
IT - Database
McLean, VA (On-Site/Office)
Recro, a Certified Small Business, helps federal agencies achieve their goals through IT infrastructure, cybersecurity, DevOps, cloud services, and digital transformation. We prioritize innovation, employee growth, and a collaborative work environment, guided by our core value - to make a difference.
Currently, Recro is seeking a motivated, career and customer oriented SIEM Data Onboarding Engineer to join our team in McLean, VA, JB Andrews, MD, Norfolk, VA, Tampa, FL, Colorado Springs, CO, Reston, VA, College Park, MD
Clearance
• TS/SCI (Willing to Obtain a CI Poly)
Responsibilities:
R equired Qualifications:
Additional Qualifications:
Benefits at Recro
Working at Recro
Currently, Recro is seeking a motivated, career and customer oriented SIEM Data Onboarding Engineer to join our team in McLean, VA, JB Andrews, MD, Norfolk, VA, Tampa, FL, Colorado Springs, CO, Reston, VA, College Park, MD
Clearance
• TS/SCI (Willing to Obtain a CI Poly)
Responsibilities:
- The Splunk Engineer is responsible for managing and enhancing our Splunk environment to ensure seamless data ingestion, analysis, and visualization.
- This role demands a deep understanding of Splunk architecture, data onboarding, and user management to support business needs and security operations.
- Design, deploy, and manage Splunk infrastructure
- Develop and maintain Splunk dashboards, queries, and alerts
- Integrate Splunk with various data sources to ensure comprehensive data ingestion
- Monitor and troubleshoot Splunk performance issues
- Collaborate with cross-functional teams to gather requirements and provide Splunk solutions
- Implement and enforce best practices for Splunk data management and retention
- Provide user training and support for Splunk-related activities
R equired Qualifications:
- 2+ years of experience in managing and configuring Splunk, 2+ years of experience in Splunk architecture: indexers, search heads, forwarders, deployment server and 1+ year with Splunk REST API for automation and operational tasks
- 2+ years configuring Cribl sources, destinations, routes and collectors
- 2+ years building pipelines to parse, normalize, enrich, mask/dedup, and route data to Splunk and other targets and
- 2+ years authoring/maintaining props.conf, transforms.conf, inputs.conf, outputs.conf and packaging Apps/TAs
- 2+ years in Linux and Windows administration: file paths, services, permissions, and log locations
- 1+ year with basic familiarity with Cribl Redmap/JavaScript functions
- 1+ year with regex skills for field extraction and event breaking
- Active TS/SCI clearance; willingness to take a polygraph exam
- Associate's degree and 5+ years of experience supporting IT projects and activities, OR
- Bachelor's degree and 3+ years of experience supporting IT projects and activities, OR
- Master's degree and 1+ years of experience supporting IT projects and activities, OR
- 10+ years of experience supporting IT projects and activities in lieu of a degree
- DoD 8570 IAT Level II certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND certification
- Must obtain a DoD 8570 Cyber Security Service Provider - Infrastructure Support certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND certification prior to start date
Additional Qualifications:
- 1 year experience with DISA STIGs or other organizational hardening standards working in regulated environments
- 2+ years Networking fundamentals: TCP/UDP, TLS, syslog transport, firewall ports and common transport issues
- 2+ years in basic troubleshooting with tools such as tcpdump/wireshark, basic vi/vim usage, setfacl, SELinux
- Knowledge of common log formats: syslog, Windows Event, JSON, CSV, XML
- Proficient in SPL for validation, troubleshooting and basic dashboards.
- Experience with scripting languages such as Python, Bash, or PowerShell
- Strong communication skills
- Load-Balancer fundamentals
- Knowledge of Git for code version control
- Knowledge of Ansible playbooks
- Knowledge of Python scripting
Benefits at Recro
- 100% paid medical, dental, and vision
- 401k - 6% matching and 401k profit sharing
- PTO - 120 Hours
- Federal Holidays
- Education and Tuition Reimbursements
- Wellness Benefits
- A lot of cool gear!
Working at Recro
- A Great Culture - We are building a culture at Recro where amazing people (like you) can do their best work. If you are ready to grow your career and recro (re-invent) the way our clients operate, you have come to the right place.
- A Great Place to Work - Employees are treated like people, not line items. We work smart when we can and hard when we must but we always do it together, as a team. We are a team with tons of passion and enthusiasm to blaze new trails and improve the state of our clients, the broader community, and even the world.
- A Great Place to Contribute - We believe diverse perspectives improve each challenge that we face. We trust and enable our amazing people to accomplish amazing feats. At Recro, you will be empowered to deliver your best work.
- A Great Place to Grow - We believe in our people and maximizing your potential. At Recro, we continue to look into the future and invest in each other through teamwork, collaboration, and training.
group id: 91090960