Job Requirements
Reston, VA
Top Secret/SCI CI Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Splunk Enteprise Security (ES) Consultant
We are seeking a Splunk Enterprise Security (ES) Consultant to support a Department of Defense customer by assessing, optimizing, and modernizing enterprise Splunk deployments. The selected candidate will provide technical leadership for Splunk Enterprise Security (ES), develop secure SIEM architectures, support Kubernetes migration efforts, normalize enterprise data for Common Information Model (CIM) compliance, optimize correlation searches and risk-based alerting, and enhance detection capabilities through AI-powered analytics, behavioral analysis, and security automation.
Responsibilities:
Required Qualifications:
We are seeking a Splunk Enterprise Security (ES) Consultant to support a Department of Defense customer by assessing, optimizing, and modernizing enterprise Splunk deployments. The selected candidate will provide technical leadership for Splunk Enterprise Security (ES), develop secure SIEM architectures, support Kubernetes migration efforts, normalize enterprise data for Common Information Model (CIM) compliance, optimize correlation searches and risk-based alerting, and enhance detection capabilities through AI-powered analytics, behavioral analysis, and security automation.
Responsibilities:
- Assess existing Splunk ES environments and implement Splunk best practices.
- Design secure architectures and integrate enterprise security tools.
- Support Splunk migration to Kubernetes.
- Configure, administer, and optimize Splunk Enterprise Security (ES).
- Normalize data for CIM compliance and onboard new data sources.
- Develop and tune correlation searches, dashboards, and risk-based alerting.
- Improve SIEM performance by reducing false positives and optimizing searches.
- Support incident response, threat hunting, and security analytics.
- Automate workflows using Splunk SOAR and Mission Control.
- Develop strategic recommendations and roadmaps for Splunk ES modernization.
Required Qualifications:
- Active TS/SCI with CI Polygraph.
- U.S. Citizenship.
- Splunk Core Consultant Certification.
- Splunk Enterprise Security Certification.
- Experience administering and optimizing Splunk Enterprise Security in enterprise environments.
- Knowledge of CIM, SIEM architecture, threat detection, incident response, and security automation.
- Experience with Kubernetes, Splunk SOAR, Mission Control, and scripting (Python or PowerShell) is highly desired.
group id: 91130387