Senior Splunk Engineer - Cleared
Apply on
Job Description
On Site Location: Annapolis MD
Clearance: TS/SCI w Poly
Summary:
A Senior Splunk Engineer excels at their job, exceeding expectations in multiple functional areas. These engineers are very knowledgeable in Splunk Core, and have enough experience and skill to support other and troubleshoot issues in unfamiliar environments on short notice.
Senior Splunk Engineers are highly regarded by customers, and willingly accept corporate assignments that provide new challenges for the individual, and business opportunities for Qmulos. They are model Qmulites who contribute to corporate and cultural aspects of Qmulos.
These engineers will be asked to support engagements of various length, and must therefore be adaptable and organized to efficiently and effectively move from one customer to the next.
A Senior Splunk Engineer must have on the job experience with, and be Accredited in at least 1 Premium Splunk Application (ES, ITSI, UBA, SOAR, Cloud), as well as the Qmulos Products Accreditation.
Responsibilities:
- Enable customer success by providing a well-rounded consulting experience from project kickoff through completion.
- Operate and maintain the Splunk log management infrastructure and leverage knowledge on a number of security technologies, information security, and networking.
- Comprehensive experience in interacting with clients, providing security focused log collection solutions using Splunk.
- Develop security focused content for complex client Splunk deployments, with focus on creation of complex detection, alerting logic and log source on-boarding using custom methods or Splunk common information model (CIM).
- Develop advanced reports to meet the requirements of key stakeholders and scalable security management tools and processes.
- Conduct research in areas, including security principles, host and network-based security technologies, machine learning algorithms, and mitigation methods.
- Automate Splunk deployments, integrations, testing of enterprise systems and services.
- Create and optimize correlation searches as an (SPL) expert.
- Establish regular, effective, comprehensive reporting for services engagements in accordance with customer requirements
- Strong organizational and time management skills
- Willingness to travel if required.
Senior Splunk Engineers are designated as Level I or Level II, determined by the additional qualifications listed below.
Senior Splunk Engineer - Level I In addition to the Senior Splunk Engineer description above, this individual has:
- Experience configuring a Splunk Premium Application (ES, ITSI, UBA, SOAR, Cloud)
- A successful track record of supporting multiple long term engagements, and seeing significant tasks through from beginning to end
- Received positive commendation from customers for a job well done
- One or more Splunk Premium App Accreditations (ES, ITSI, UBA, SOAR, Cloud)
- Qmulos Products Accreditations (Q-Compliance and Q-Audit)
Senior Splunk Engineer - Level II In addition to the Senior Splunk Engineer and Level I descriptions above, this individual has:
- Experience deploying and configuring a Splunk Premium Application (ES, ITSI, UBA, SOAR)
- Proven capable of repairing damaged rapport with customers, and improving Splunk-to-customer and consultant-to-customer relations
- Provided opportunities for the Qmulos Sales Team to pursue new customers
- Two or more Splunk Premium App Accreditations (ES, ITSI, UBA, SOAR, Cloud)
- Provided consistent technical support to fellow services engineers
- Shown leadership tendencies and is looked to as an exemplary consultant and Splunk expert
Required Skills/Abilities:
- U.S. Citizenship or Permanent Resident status REQUIRED
- 5+ years of technical consulting or big data analytics experience
- 2+ years of hands-on experience with Splunk, network security and system security, supporting security information and event management tools (SIEMs)
- 2+ years of experience with rule and advanced logic creation within Splunk
- Knowledge of Splunk and JIRA best practices
- Experience with Linux and Windows operating systems
- Experience with using scripting languages to automate tasks and manipulate data
- Experience with working in a large enterprise environment
- Experience with integrating solutions in a multi-vendor environment, including SaaS environments
- Experience with regular expressions
- Knowledge of enterprise system and network logging, with a focus on security event logging
- Knowledge of Splunk common information model (CIM)
- Ability to work independently in fast-paced, structured and unstructured environments
- Splunk User, Power User, Administrator Certifications (Ability to achieve Splunk Core Certified Consultant)
- 2+ years of experience in security operations
- Experience with enterprise-scale operations and maintenance environments
- Experience with command-line interface
- Experience with Splunk API
- Experience with Python
- Experience with various security tools, including Wireshark, Nessus, Nmap, Burp, Proxy, or Snort (preferred)
- Experience with SPL, SQL, and other related search languages
- Knowledge of networking protocols
- Ability to be a Splunk language (SPL) expert
- Familiarity with concepts and implementation of Syslogd
- Knowledge of virtualization and container tools, including VMware, Parallels, VirtualBox, OpenStack, and Docker
- Knowledge of configuration management tools, including Ansible, Puppet, Chef, and SaltStack
- BA or BS degree in CS, IT, Engineering, or a related field; or equivalent professional experience. Advanced degree is a plus.
- Industry recognized security certifications (security, networking, etc)- preferred
- Working knowledge of Splunk Cloud solution
- Working knowledge of AWS
EEO Statement: Qmulos is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.