Cybersecurity Engineer – SIEM / Splunk
Position Summary
Electrosoft is seeking a Cybersecurity Engineer specializing in Security Information and Event Management (SIEM) and Enterprise Log Management (ELM) to support a large-scale DoD cybersecurity environment.
The engineer will provide architecture, engineering, administration, content development, troubleshooting, integration, and sustainment support for Splunk Core and Splunk Enterprise Security (ES).
Key Responsibilities
- Research, plan, install, configure, troubleshoot, maintain, and back up components of the enterprise Splunk ELM/SIEM environment.
- Enhance ELM and SIEM architecture by incorporating new data feeds, products, and security capabilities.
- Integrate security event and data feeds into the Splunk environment.
- Develop and implement SIEM use cases to improve cybersecurity situational awareness.
- Develop customized dashboards, reports, data monitors, active channels, trends, correlation rules, and other SIEM content.
- Analyze threat information from logs, IDS, intelligence reporting, vendor sources, and other cybersecurity sources.
- Identify and elevate high-threat events to incident responders.
- Perform event analysis and tuning to improve detection capabilities and reduce false positives.
- Support the development and optimization of security rules and correlation capabilities.
- Perform upgrades, maintenance, troubleshooting, and performance tuning of SIEM infrastructure.
- Conduct network and capacity analysis to ensure the environment can support anticipated event volumes.
- Analyze endpoint availability and data-collection capabilities.
- Define and maintain appropriate user roles and access.
- Evaluate data-storage requirements and their impact on SIEM architecture.
- Support Security Test and Evaluation and Information Assurance assessments.
- Review DoD policies and assess their impact on SIEM and cybersecurity architecture.
- Develop and maintain technical standards, security architecture documentation, SOPs, and implementation documentation.
- Conduct research and market analysis of emerging cybersecurity and SIEM technologies.
- Provide technical training, briefings, and knowledge transfer to Government and contractor personnel.
Basic Qualifications:
- Seven (7) years of relevant IT experience
- DOD Secret Clearance
- Must be eligible for IT I
- Relevant certification meeting DOD 8570/8140 IAT level III
- Relevant certification meeting DOD 8570/8140 CND-IS
- Computing Environment: Linux+, Splunk Administrator
- Experience creating custom dashboards and reports in Splunk using threat data
- Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).