SIEM Engineer-Atlanta, GA
iSenpai, LLC - SBA WOSB · Atlanta, GA · 4 mo ago
EngineeringFull-time
Skills
- Enterprise IT and cyber security services
- Cloud technology and data analytics solutions
- Agile DevSecOps
- NIST Special Publication (SP) 800-53 and Risk Management Framework (RMF)
- Health, Dental, Vision, HSA Contribution, 401K match, and more comprehensive benefits
- Computer-based training (CBT) library on IT and information security topics and certifications
- Flexible / Alternative Work Schedules
- Equal opportunity / affirmative action employer
Responsibilities
- Provide Splunk Engineering support to partner with security tools and infrastructure management teams
- Administer and manage the department's Splunk solution
- Facilitate data ingestion, analysis, correlation, and visualizations
- Maintain, upgrade, and operate Splunk systems
- Provide guidance and assistance across teams
- Integrate automation, applications, and systems monitoring
- Develop guidance on data analysis and reporting
- Enable a Department Security Information and Event Management (SIEM) program utilizing Splunk Enterprise Security Tools
- Design and implement content management solutions
- Design and implement technical infrastructure based on functional requirements
- Assist with Data Enrichment
- Provide extensive knowledge of Splunk and educate Splunk users
- Assist with integration and use of Automation tools
- Experience with NOC technologies and metrics
- Desire to learn advanced SOC methodologies using Splunk ES
- Experience with Security Orchestration, Automation and Response (SOAR) tools and technologies
Qualifications
- Bachelor's Degree in Information Technology or related field
- 4 years of SIEM/Cyber Security engineering experience
- U.S. citizen with an active DoD Public Trust Clearance
- Flexibility to meet any threat scenario 24/7/365 as mission dictates
- Experience with cloud-based technologies (AWS, Azure)
- Prefer candidate to possess one or more of the following certifications: Certified Ethical Hacker (CEH) or other equivalent cyber certification(s), Splunk Core Certified Consultant, Cribl Certified User, Security Tool Certifications (e.g., Cisco, Palo Alto, etc), Experience integrating and using Automation tools (Ansible, Terraform), Experience with NOC technologies and metrics, Desire to learn advanced SOC methodologies using Splunk ES, Experience with Security Orchestration, Automation and Response (SOAR) tools and technologies (e.g. Splunk Phantom, Ansible, Python, etc.)