SIEM(Security Information & Event Management) Engineer
Leidos has an exciting and challenging opportunity for an SIEM (Security Information and Event Management) Engineer in our Intel Sector’s Cyber & Analytics Business Area (CABA). Our team is at the forefront of Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management.
About the role
The selected candidate will join a high-performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, fast-paced program. Program execution follows DEVOPS best practices and employs robust development, test, and production environments. The program uses Behavior Driven Development (BDD) and test automation tools alongside a full suite of team collaboration tools. It provides system engineering, development, test, integration, and operational support for a program focused on injecting new technology and adding advanced capabilities while continuing to support an ongoing mission and operational system.
Responsibilities
- Configure the collection, parsing, correlation, and visualization of event data for a critical operational system.
- Apply expertise in system administration, log management, event correlation, and threat detection to support the development and sustainment of capabilities that analyze collected data, generate actionable insights, and determine whether monitored systems are operating as expected.
- Support the configuration of systems used by analysts and end users, as well as the collection and extraction of data to enhance existing and future reports, analytics, and dashboards.
- Contribute to the design and development of reporting solutions based on end-user requirements.
- Work across teams to improve the definition and quality of audit data being collected, with the goal of reducing false positives and false negatives and strengthening the overall accuracy and effectiveness of system monitoring.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, Network Engineering, or a related field, and at least 12 years of relevant experience. Additional experience may be substituted for a degree.
- At least 5 years of experience with one or more of the following technologies: StealthWatch, TripWire, Zenoss, ArcSight, Splunk.
- Experience in the engineering and administration of Splunk.
- Hands-on experience implementing and supporting Splunk multi-site clusters, including indexer clustering, site awareness, replication/search factors, and cross-site failover.
- Experience designing, implementing, and supporting Splunk core components, including indexers, forwarders, search heads, and cluster managers.
- Experience configuring and administering Splunk data ingestion and forwarding for both new and existing applications and data sources.
- Proven ability to troubleshoot Splunk dataflow issues across core platform components.
- Experience configuring and deploying data collection across a variety of operating systems and network platforms.
- In-depth experience creating dashboards and analytics within SIEM tools.
- Experience working with monitoring systems that support auditing, incident response, and system health monitoring.
- Solid understanding of network components, devices, ports, protocols, and basic networking troubleshooting steps.
- Demonstrated ability to troubleshoot issues related to log feeds, search performance, and field extractions.
- Ability to resolve issues related to data solutions and data quality.
- Active TS/SCI with Polygraph clearance.
Preferred Qualifications
- Splunk Certified Administrator certification.
- Experience working in a Network Security Operations Center (SOC).
- Demonstrated skill in data visualization.
- Extensive experience developing incident response workflows within a SIEM tool.
- CompTIA Security+ Certification.
- GIAC Certified Incident Handler (GCIH) Certification.
- GIAC Cyber Threat Intelligence (GCTI) Certification.
- Formal SIEM training.
- Experience working in an Agile team or program environment.
Benefits
- Paid Time Off.
- 11 paid holidays.
- 401K with a 6% company match and immediate vesting.
- Flexible schedules.
- Discounted Stock Purchase Plans.
- Technical upskilling, education, and training support.
- Parental paid leave.
Pay
Pay Range: $131,300.00 - $237,350.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.