A

Cybersecurity Engineer 4 - SIEM / SPLUNK Engineer

Posted 2 months ago

Job Requirements

Columbus, OH Richmond, VA
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Cybersecurity Engineer 4 performs a variety of routine project tasks applied to specialized cybersecurity problems. Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to cybersecurity requirements. Analyzes information security requirements. Applies analytical and systematic approaches in the resolution of problems of workflow, organization, and planning. Provides security engineering support for planning, design, development, testing, demonstration, integration of information systems. Analyzes threat information gathered from logs, Intrusion Detection Systems (IDS), intelligence reports, vendor sites, and a variety of other sources. Creates customized dashboards using Security Information and Event Management (SIEM) tool Splunk ES to elevate high threat items to incident responders. Administration knowledge of the Splunk ES and backend database infrastructure related to upgrades and daily maintenance is essential. Provide analysis and make recommendations in line with the roles of CERT Incident Handlers (IH) and site Information Assurance Managers (IAM). Develop ES rules, reports, dashboards, data monitors, active channels, trends and use cases to identify threats and optimize data mining across DLA. Will research, plan, install, configure, troubleshoot, maintain and backup all components in the DLA Splunk Enterprise Log Management (ELM) architecture.

Required Qualifications:
• Seven (7) years of relevant IT experience

• DOD Secret Clearance

• Must possess IT-I Critical Sensitive security clearance or Tier 5 (T5)

• 8140 Baseline Certification: Primary DCWF Work Role 521: Cyber Defense Infrastructure Support - Proficiency Level: Intermediate
Candidate must possess one of the following certifications:
o CEH, Cloud+, CySA+, PenTest+, SSCP, Security+, and GSEC
Note: higher or advanced GIAC or CISSP concentrations also satisfy the intermediate requirement

• 8140 Baseline Certification for Primary DCWF Secondary DCWF Work Role 451: System Administrator - Proficiency Level: Intermediate
Candidate must possess one the following certifications:
o CompTIA Security+, CompTIA Cloud+
o GIAC Security Essentials (GSEC)

• Computing Environment Certification: Linux+, Splunk Administrator

• Experience creating custom dashboards and reports in Splunk using threat data

• Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES)
group id: 10280020