Jobs
>
Ajaccio

    SIEM Engineer - Annapolis Junction, United States - Wood Consulting

    Default job background
    Description

    Overview


    SIEM (Security Information & Event Management) Engineer / Splunk Certified Admin

    The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong skills in system administration, log management, event correlation, and threat detection and will support building and maintaining a system that analyzes collected data and derives facts, inferences, and projections to determine if the systems being monitored are operating normally. The individual will work on a team responsible for configuring the systems which support analysts and end‐users. The successful candidate will support the collection and extraction of data used to refine existing and new reports, analytics, and dashboards, and will be involved with the drafting and creation of reports and dashboards based on end‐user requirements. She/he will also support the integration of resources across teams to better define the audit data being collected to eliminate false positives and false negatives from the data.

    Security Clearance Requirements:

    This position requires candidates to be U.S. Citizens and possess a TS/SCI Security Clearance with an appropriate Polygraph.

    Qualifications


    Basic / Required Qualifications

    • Must have Splunk Enterprise Certified Admin Certificate or higher.
    • At least 8 years of related experience.
    • At least 2 years of experience with one or more of the following: StealthWatch, TripWire, Zenoss, ArcSight, Splunk.
    • Experience in design, implementation, and support of Splunk core components, including: indexers, forwarders, search heads, and cluster managers.
    • Experience with configuration and administration of Splunk ingestion and forwarding for new and existing applications and data.
    • Experience with troubleshooting Splunk dataflow issues between the various Splunk core components.
    • Experience configuring and deploying data collection for a variety of operating systems and networking platforms.
    • Experience creating Dashboards and Analytics within SIEM tools.
    • Experience working with monitoring systems supporting auditing, incident response, and system health.
    • Understanding of networking components and devices, ports, protocols, and basic networking troubleshooting steps.
    • The ability to troubleshoot issues with log feeds, search time, and field extractions.
    • The ability to troubleshoot problems related to data solutions.

    Preferred Qualifications

    • Bachelor's Degree in Computer Science, Engineering, Information Assurance, or a related discipline.
    • Network Security Operations Center (SOC) experience.
    • Experience and talent in data visualization.
    • Experience creating workflows for Incident Response within a SIEM Tool.
    • Security+ Certification.
    • GIAC Certified Incident Handler Certification.
    • GIAC Cyber Threat Intelligence Certification.
    • Cybersecurity certifications.
    • Formal SIEM training.
    • Experience working on an Agile team/program.

    WOOD is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.



  • CyberCore Technologies Annapolis Junction, United States

    **TS/SCI Clearance w/Polygraph Required** Job Summary / Primary Responsibilities The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong skills i ...


  • Navstar Annapolis Junction, United States

    Would you like to perform rewarding work while contributing to the success of an established, growing company? Navstar is an award-winning organization that has a proven track record of successfully providing IT services and solutions both as a prime and sub-contractor on mission ...


  • BAE Systems USA Annapolis Junction, United States

    Job Description The selected candidate will join a high performing agile team that uses the Scaled Agile Framework (SAFe) methodology to support a nationally significant and fast-paced program. Program execution follows DEVOPS best practices and employs robust development, test ...


  • BAE Systems USA Annapolis Junction, United States

    Job Description The selected candidate will join a high performing agile team that uses the Scaled Agile Framework (SAFe) methodology to support a nationally significant and fast-paced program. Program execution follows DEVOPS best practices and employs robust development, test ...


  • Leidos Annapolis Junction, United States

    · Destination...Leidos Come join our exciting and fast-growing National Security Group · Why? Because we offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and developme ...


  • Leidos Annapolis Junction, United States

    Destination...Leidos Come join our exciting and fast-growing National Security Group · Why? Because w e offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and development ...


  • Leidos Annapolis Junction, United States

    R Description Destination...Leidos Come join our exciting and fast-growing National Security Group Why? Because w e offer competitive salaries, bonus programs, competitive paid leave, holidays, beyond ordinary benefits, and many opportunities for continual professional growth and ...


  • Open Systems Technologies Annapolis Junction, United States

    Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with soft ...


  • Open Systems Technologies Corporation Annapolis Junction, United States

    Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with soft ...


  • Momentum Engineering Annapolis Junction, United States

    Required Qualification Must have Splunk Enterprise Certified Admin Certificate or higher. The selected candidate will be responsible for configuring the collection, parsing, correlation, and visualization of events for a critical operational system. She/he will demonstrate strong ...

  • Leidos

    Splunk Administrator

    2 weeks ago


    Leidos Annapolis Junction, United States

    Description · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exec ...

  • General Dynamics Information Technology

    SIEM Team

    23 hours ago


    General Dynamics Information Technology Annapolis Junction, United States

    SIEM Team - Splunk Systems EngineerDeliver simple solutions to complex problems as a SIEM Team - Splunk Systems Engineer at GDIT. Here, you'll tailor cutting-edge solutions to the unique requirements of our clients. With a career in application development, you'll make the end us ...

  • Leidos

    Splunk Administrator

    2 weeks ago


    Leidos Annapolis Junction, United States

    Description · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exe ...


  • Leidos Annapolis Junction, United States

    R Description The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exec ...

  • General Dynamics Information Technology

    SIEM Team

    1 day ago


    General Dynamics Information Technology Annapolis Junction, United States

    SIEM Team - Splunk Systems Engineer · Deliver simple solutions to complex problems as a SIEM Team - Splunk Systems Engineer at GDIT. Here, you'll tailor cutting-edge solutions to the unique requirements of our clients. With a career in application development, you'll make the end ...


  • EverWatch Annapolis Junction, United States

    Job Title: · Security Operations Center (SOC) Analyst, Senior · Overview: · EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our countrys most critical missions. We are a full-service government solutions company. Ha ...

  • Leidos

    Splunk Administrator

    2 weeks ago


    Leidos Annapolis Junction, United States Full time

    Description · The Program is looking for a SIEM (Security Information and Event Management) Engineer / Splunk Certified Admin to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology to support a large, complex, and fast-paced program. Program exe ...


  • cFocus Software Incorporated Annapolis Junction, United States

    cFocus Software is seeking an Information Systems Security Engineer to join our program in Annapolis Junction, MD. This position requires an active TS/SCI CI Poly clearance. · Responsibilities: · Advise on in-depth security design review and threat/risk assessments. · Provide ...


  • teKnoluxion Annapolis Junction, United States

    Overview: · Location: Work to be performed at Ft. Meade, in Ops 1 and Oracle's office in Annapolis Junction Security Clearance Required: TS-SCI with FS poly **This position is not open for any clearance upgrades or sponsorship.** teKnoluxion provides the Defense and Intelligence ...


  • Synergy ECP Annapolis Junction, United States

    Information Systems Security Engineer (ISSE) Level 2 · Annapolis Junction, MD ) · Description · The Information Systems Security Engineer shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with ...