Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk
Position Summary
Electrosoft is seeking a Cybersecurity Engineer specializing in Security Information and Event Management (SIEM) and Enterprise Log Management (ELM) to support a large-scale DoD cybersecurity environment.
The engineer will provide architecture, engineering, administration, content development, troubleshooting, integration, and sustainment support for Splunk Core and Splunk Enterprise Security (ES).
Key Responsibilities
Research, plan, install, configure, troubleshoot, maintain, and back up components of the enterprise Splunk ELM/SIEM environment.
Enhance ELM and SIEM architecture by incorporating new data feeds, products, and security capabilities.
Integrate security event and data feeds into the Splunk environment.
Develop and implement SIEM use cases to improve cybersecurity situational awareness.
Develop customized dashboards, reports, data monitors, active channels, trends, correlation rules, and other SIEM content.
Analyze threat information from logs, IDS, intelligence reporting, vendor sources, and other cybersecurity sources.
Identify and elevate high-threat events to incident responders.
Perform event analysis and tuning to improve detection capabilities and reduce false positives.
Support the development and optimization of security rules and correlation capabilities.
Perform upgrades, maintenance, troubleshooting, and performance tuning of SIEM infrastructure.
Conduct network and capacity analysis to ensure the environment can support anticipated event volumes.
Analyze endpoint availability and data-collection capabilities.
Define and maintain appropriate user roles and access.
Evaluate data-storage requirements and their impact on SIEM architecture.
Support Security Test and Evaluation and Information Assurance assessments.
Review DoD policies and assess their impact on SIEM and cybersecurity architecture.
Develop and maintain technical standards, security architecture documentation, SOPs, and implementation documentation.
Conduct research and market analysis of emerging cybersecurity and SIEM technologies.
Provide technical training, briefings, and knowledge transfer to Government and contractor personnel.
Basic Qualifications:
Seven (7) years of relevant IT experience
DOD Secret Clearance
Must be eligible for IT I
Relevant certification meeting DOD 8570/8140 IAT level III
Relevant certification meeting DOD 8570/8140 CND-IS
Computing Environment: Linux+, Splunk Administrator
Experience creating custom dashboards and reports in Splunk using threat data
Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).
Pay Range
$150,000—$160,000 USD