SIEM(Security Information & Event Management) Engineer
$131,300–$237,350 year
On-siteAnnapolis Junction, Maryland, United States
Job Summary
Configure the collection, parsing, correlation, and visualization of event data for a critical operational system using Splunk multi-site clusters. Apply expertise in system administration and log management to support the development and sustainment of capabilities that analyze collected data and generate actionable insights. Work across teams to improve audit data quality, reduce false positives and negatives, and strengthen system monitoring effectiveness while designing reporting solutions based on end-user requirements. Support the configuration of systems used by analysts and the extraction of data to enhance existing and future reports and dashboards.
Required Qualifications
- Bachelor's degree in Computer Science, Software Engineering, Network Engineering, or a related field
- At least 12 years of relevant experience
- At least 5 years of experience with one or more of the following technologies: StealthWatch, TripWire, Zenoss, ArcSight, Splunk
- Must have experience in the engineering and administration of Splunk
- Hands-on experience implementing, and supporting Splunk multi-site clusters, including indexer clustering, site awareness, replication/search factors, and cross-site failover
- Experience designing, implementing, and supporting Splunk core components, including indexers, forwarders, search heads, and cluster managers
- Experience configuring and administering Splunk data ingestion and forwarding for both new and existing applications and data sources
- Proven ability to troubleshoot Splunk dataflow issues across core platform components
- Experience configuring and deploying data collection across a variety of operating systems and network platforms
- In-depth experience creating Dashboards and Analytics within SIEM tools
- Experience working with monitoring systems that support auditing, incident response, and system health monitoring
- Must have a solid understanding of network components, devices, ports, protocols, and basic networking troubleshooting steps
- Demonstrated ability to troubleshoot issues related to log feeds, search performance, and field extractions
- Must have the ability to resolve issues related to data solutions and data quality
- Must have TS/SCI with Polygraph
Desired Qualifications
- Splunk Certified Administrator certification
- Experience working in a Network Security Operations Center (SOC)
- Demonstrated skill in data visualization
- Extensive experience developing incident response workflows within a SIEM Tool
- CompTIA Security+ Certification
- GIAC Certified Incident Handler (GCIH) Certification
- GIAC Cyber Threat Intelligence (GCIT) Certification
- Formal SIEM training
- Experience working in an Agile team or program environment
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.