Cribl Engineer
About the Role
Are you excited at the prospect of developing innovative solutions to enable secure and reliable operations of enterprise computer systems? Are you fascinated by the possibilities presented by engineering, designing, development, and implementation of enterprise network cyber defense capabilities to prevent sophisticated cyber threats? In an increasingly connected world, it is critical to understand the fundamentals of layered defense and Zero Trust technologies.
As a Splunk and Cribl Engineer, you will prevent adversary network threats, identify advanced attack vectors, and thwart methods of exploitation. You’ll work individually or in a small integrated team, lead tasks or projects, and provide guidance to lower-level technicians and specialists. You’ll ensure project completion and apply expertise in engineering, design, development, and implementation of enterprise network cyber defense capabilities.
Responsibilities
- Build and maintain data pipelines using tools such as Cribl
- Engineer, design, develop, and implement enterprise network cyber defense capabilities
- Apply familiarity with cyber defense tools and technologies, including:
- Web content filters and email security capabilities
- Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
- Host Based Security Systems (HBSS) and Security Incident and Event Management (SIEM) tools
- Domain Name System (DNS) security practices
- Advanced log analysis, network monitoring, and network flow analysis
- Packet capture analysis and network proxies
- Firewalls and anti-virus capabilities
- Linux/UNIX command line and access control lists
- Work with STIGs, SCAP, and cybersecurity best practices
- Automate security configurations for Linux and Windows systems
- Recommend and implement remediations for non-compliant security controls
Requirements
- 3+ years of experience building data pipelines using tools such as Cribl
- Experience with Windows and Linux, including installing, configuring, or maintaining server operating systems and applications
- TS/SCI clearance
- High School diploma or GED
- DoD 8570 IAT II compliant certification (e.g., Security+, CCNA Security, or GSEC)
Nice to Have
- Experience with Kubernetes
- Experience with big data analytics, machine learning, artificial intelligence, or anomaly detection
- Scripting experience in PowerShell, BASH, Python, or Perl
- Experience in Department of Defense (DoD), Intelligence Community, or other regulated environments
- Knowledge of Zero Trust Architecture (ZTA) principles
Benefits
- Health, life, disability, and retirement benefits
- Paid leave, professional development, and tuition assistance
- Work-life programs and dependent care
- Recognition awards program for exceptional performance and demonstration of company values
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet this threshold are only eligible for select offerings, not inclusive of health benefits.
Pay
The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). Salary is determined by various factors, including location, education, knowledge, skills, competencies, experience, contract-specific affordability, and organizational requirements.
Schedule
This posting will close within 90 days from the posting date.
Work models include:
- Remote: Primarily remote work, with occasional in-person requirements at a Booz Allen or customer facility.
- Hybrid: Frequent work from a Booz Allen facility, with potential visits to customer facilities as needed.
- Onsite: Work primarily performed at a Booz Allen office or customer facility, with direct collaboration required.
For virtual work, cameras are generally expected to be on during meetings to support engagement and communication.