The Splunk Engineer will provide overall back-end engineering, and administration in supporting a fairly distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security premium app, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.
The Splunk Engineer will be a member of the Enterprise Splunk team, Cybersecurity Engineering team members and will be required to interact with end users to gather requirements, perform troubleshooting, and provide assistance with the creation of Splunk search queries and dashboards. The Splunk Engineer may be required interact with senior management, as necessary. The Splunk Back-End Administrator will provide support to civilian agency’s Enterprise Operations and Engineering branches. The candidate will be responsible for managing the day-to-day operations of the Enterprise Splunk system spanning data centers, service centers and cloud services.
A minimum of a Bachelor’s degree coupled with 10+ years’ experience in the Information Technology arena or Masters Degree with 8 years of relevant experience:
- 5 years of experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments
- 5 Years’ experience in Linux and SQL/ODBC interfaces
- 4 Years’ experience in app interface development, using REST API’s
- Ability to follow Change & Configuration Management.
- Strong problem solving abilities with an analytic and qualitative eye for reasoning under pressure.
- Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision
- Knowledge of Cloud Services such as AWS, Azure, Office365
- Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
- Must hold one or more of the following Splunk Certifications: Admin, Architect, Developer
Preferred 6c Public Trust or Top Secret Clearance.
- Experience in SQL
- Current or former completed Splunk training
- Prior experience a in Splunk professional services role
- Experience in automating Splunk Deployments and orchestration with in a Cloud environment