Job Requirements
Washington, DC
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
GCYber is seeking a Senior Splunk Administrator, to support a high-profile government customer. This is a hands-on administration role responsible for data ingestion, dashboard development, and resolving issues when data is missing, delayed, duplicated, or incorrectly parsed.
As the Senior Splunk Administrator, you will:
As the Senior Splunk Administrator, you will:
- Administer and monitor an enterprise Splunk environment, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, deployers, cluster managers, and monitoring consoles.
- Troubleshoot missing, delayed, duplicated, incorrectly parsed, or incorrectly routed data across the complete ingestion path.
- Configure and maintain Splunk inputs, outputs, indexes, sourcetypes, routing, filtering, timestamp extraction, and event parsing.
- Build and maintain Splunk dashboards, reports, alerts, and saved searches that provide useful operational and cybersecurity visibility.
- Work with stakeholders to define dashboard requirements, identify the right data, and present results in a clear and actionable format.
- Develop and optimize SPL searches that support dashboards, data validation, troubleshooting, trend analysis, and operational reporting.
- Diagnose issues involving forwarders, blocked queues, certificates, network connectivity, indexing, permissions, dashboards, and search logic.
- Active DoD Top Secret/SCI clearance
- Active IAT II certification (i.e., Security+, CySA+, CCNA-Security, GSEC, CND, GICSP, SSCP)
- Bachelor's Degree in Computer Science, Cybersecurity, Computer. Engineering, Information Technology, or equivalent degree
- 5+ years of Splunk administration or engineering experience.
- Hands-on experience supporting a distributed enterprise Splunk environment
- Experience with indexer clusters, search head clusters, heavy forwarders, universal forwarders, deployment servers, and related Splunk components.
- Splunk certification preferred
group id: 90817175