- Must have Splunk Enterprise Certified Admin Certificate or higher.
- At least 8 years of related experience.
- At least 2 years of experience with one or more of the following: StealthWatch, TripWire, Zenoss, ArcSight, Splunk.
- Experience in design, implementation, and support of Splunk core components, including: indexers, forwarders, search heads, and cluster managers.
- Experience with configuration and administration of Splunk ingestion and forwarding for new and existing applications and data.
- Experience with troubleshooting Splunk dataflow issues between the various Splunk core components.
- Experience configuring and deploying data collection for a variety of operating systems and networking platforms.
- Experience creating Dashboards and Analytics within SIEM tools.
- Experience working with monitoring systems supporting auditing, incident response, and system health.
- Understanding of networking components and devices, ports, protocols, and basic networking troubleshooting steps.
- The ability to troubleshoot issues with log feeds, search time, and field extractions.
- The ability to troubleshoot problems related to data solutions.
- Bachelor's Degree in Computer Science, Engineering, Information Assurance, or a related discipline.
- Network Security Operations Center (SOC) experience.
- Experience and talent in data visualization.
- Experience creating workflows for Incident Response within a SIEM Tool.
- Security+ Certification.
- GIAC Certified Incident Handler Certification.
- GIAC Cyber Threat Intelligence Certification.
- Cybersecurity certifications.
- Formal SIEM training.
- Experience working on an Agile team/program.
-
CyberCore Technologies Annapolis Junction, United States**TS/SCI Clearance w/Polygraph Required** Job Summary / Primary Responsibilities The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong skills i ...
-
Navstar Annapolis Junction, United StatesWould you like to perform rewarding work while contributing to the success of an established, growing company? Navstar is an award-winning organization that has a proven track record of successfully providing IT services and solutions both as a prime and sub-contractor on mission ...
-
BAE Systems USA Annapolis Junction, United StatesJob Description The selected candidate will join a high performing agile team that uses the Scaled Agile Framework (SAFe) methodology to support a nationally significant and fast-paced program. Program execution follows DEVOPS best practices and employs robust development, test ...
-
BAE Systems USA Annapolis Junction, United StatesJob Description The selected candidate will join a high performing agile team that uses the Scaled Agile Framework (SAFe) methodology to support a nationally significant and fast-paced program. Program execution follows DEVOPS best practices and employs robust development, test ...
-
Leidos Annapolis Junction, United States· Destination...Leidos Come join our exciting and fast-growing National Security Group · Why? Because we offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and developme ...
-
Leidos Annapolis Junction, United StatesDestination...Leidos Come join our exciting and fast-growing National Security Group · Why? Because w e offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and development ...
-
Leidos Annapolis Junction, United StatesR Description Destination...Leidos Come join our exciting and fast-growing National Security Group Why? Because w e offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and ...
-
SEIM Engineer/Splunk Certified Admin
1 week ago
Open Systems Technologies Annapolis Junction, United StatesOpen Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with soft ...
-
Open Systems Technologies Corporation Annapolis Junction, United StatesOpen Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with soft ...
-
Momentum Engineering Annapolis Junction, United StatesRequired Qualification Must have Splunk Enterprise Certified Admin Certificate or higher. The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong ...
-
Splunk Administrator
2 weeks ago
Leidos Annapolis Junction, United StatesDescription · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exec ...
-
SIEM Team
23 hours ago
General Dynamics Information Technology Annapolis Junction, United StatesSIEM Team - Splunk Systems EngineerDeliver simple solutions to complex problems as a SIEM Team - Splunk Systems Engineer at GDIT. Here, you'll tailor cutting-edge solutions to the unique requirements of our clients. With a career in application development, you'll make the end us ...
-
Splunk Administrator
2 weeks ago
Leidos Annapolis Junction, United StatesDescription · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exe ...
-
Splunk Administrator
1 week ago
Leidos Annapolis Junction, United StatesR Description The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exec ...
-
SIEM Team
1 day ago
General Dynamics Information Technology Annapolis Junction, United StatesSIEM Team - Splunk Systems Engineer · Deliver simple solutions to complex problems as a SIEM Team - Splunk Systems Engineer at GDIT. Here, you'll tailor cutting-edge solutions to the unique requirements of our clients. With a career in application development, you'll make the end ...
-
Security Operations Center
6 days ago
EverWatch Annapolis Junction, United StatesJob Title: · Security Operations Center (SOC) Analyst, Senior · Overview: · EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our countrys most critical missions. We are a full-service government solutions company. Ha ...
-
Splunk Administrator
2 weeks ago
Leidos Annapolis Junction, United States Full timeDescription · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exe ...
-
Information Security Systems Engineer
4 days ago
cFocus Software Incorporated Annapolis Junction, United StatescFocus Software is seeking an Information Systems Security Engineer to join our program in Annapolis Junction, MD. This position requires an active TS/SCI CI Poly clearance. · Responsibilities: · Advise on in-depth security design review and threat/risk assessments. · Provide ...
-
Cloud Security Consultant
6 days ago
teKnoluxion Annapolis Junction, United StatesOverview: · Location: Work to be performed at Ft. Meade, in Ops 1 and Oracle's office in Annapolis Junction Security Clearance Required: TS-SCI with FS poly **This position is not open for any clearance upgrades or sponsorship.** teKnoluxion provides the Defense and Intelligence ...
-
Information Systems Security Engineer
3 weeks ago
Synergy ECP Annapolis Junction, United StatesInformation Systems Security Engineer (ISSE) Level 2 · Annapolis Junction, MD ) · Description · The Information Systems Security Engineer shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with ...
SIEM Engineer - Annapolis Junction, United States - Wood Consulting
Description
Overview
SIEM (Security Information & Event Management) Engineer / Splunk Certified Admin
The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong skills in system administration, log management, event correlation, and threat detection and will support building and maintaining a system that analyzes collected data and derives facts, inferences, and projections to determine if the systems being monitored are operating normally. The individual will work on a team responsible for configuring the systems which support analysts and end‐users. The successful candidate will support the collection and extraction of data used to refine existing and new reports, analytics, and dashboards, and will be involved with the drafting and creation of reports and dashboards based on end‐user requirements. She/he will also support the integration of resources across teams to better define the audit data being collected to eliminate false positives and false negatives from the data.
Security Clearance Requirements:
This position requires candidates to be U.S. Citizens and possess a TS/SCI Security Clearance with an appropriate Polygraph.
Qualifications
Basic / Required Qualifications
Preferred Qualifications
WOOD is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.