- Location
- Suitland, Maryland, United States
- Department
- Professional Services
- Experience
- 10+ years
- Clearance
- Required
- Source
- Greenhouse
Description
Splunk Administrator (Level 3)
G2IT is seeking an experienced Splunk Administrator (Level 3) to support enterprise cybersecurity, monitoring, and data analytics environments. The ideal candidate will have extensive hands-on experience administering and optimizing Splunk environments, supporting Cyber Network Defense (CND) operations, and working within DoD or Intelligence Community environments.
Key Responsibilities
- Install, integrate, configure, administer, maintain, monitor, troubleshoot, and optimize Splunk environments.
- Support Splunk Enterprise and advanced applications, including Enterprise Security (ES), SOAR, UEBA, and IT Service Intelligence (ITSI).
- Install and manage Splunk Technical Add-ons (TAs), Apps, and Universal Forwarders.
- Develop SPL queries, dashboards, reports, alerts, and other monitoring capabilities.
- Perform log management, ingestion, parsing, normalization, and analysis.
- Create REGEX parsing and XML presentations of log data.
- Maintain Splunk Common Information Model (CIM) compliance and perform automated and manual data mapping.
- Utilize Python scripting to automate Linux and Splunk administration tasks.
- Work with Splunk DB Connect, SQL, and database integrations to collect and analyze log data.
- Create, install, and maintain encryption keys used to secure communication channels.
- Perform Risk Management Framework (RMF) functions associated with Splunk environments.
- Support AWS resources and Red Hat Enterprise Linux environments.
- Troubleshoot LAN/WAN, networking protocols, ports, services, file systems, and Windows/Unix/Linux infrastructure.
- Develop technical documentation, SOPs, best practices, presentations, and cybersecurity guidance.
- Support System/Software Development Life Cycle (SDLC) processes.
- Communicate complex cybersecurity and technical issues to management, mission stakeholders, and customers.
Required Qualifications
- Must hold an active Top Secret (TS) security clearance and be eligible for TS/SCI access.
- 10+ years of professional experience with LAN/WAN technologies, networking protocols, file systems, ports, services, and commands within Windows and Unix/Linux environments.
- 8+ years of concentrated experience within the Cyber Network Defense (CND) discipline.
- 6+ years of professional hands-on experience with Splunk administration, integration, configuration, maintenance, and optimization.
- Expert-level knowledge of Splunk Enterprise and Splunk applications, including ES, SOAR, UEBA, and ITSI.
- Extensive experience with Splunk Add-ons, Apps, Technical Add-ons (TAs), and Universal Forwarders.
- Strong experience creating SPL queries, dashboards, reports, and alerts.
- Experience with REGEX parsing and XML presentation of log data.
- Experience using Python to automate Linux and Splunk administrative tasks.
- Experience with Splunk DB Connect, SQL, and database log collection.
- Experience with Splunk Common Information Model (CIM) compliance and data mapping.
- Experience creating and managing encryption keys for secure communications.
- Experience administering and managing AWS and Red Hat Enterprise Linux environments.
- Significant experience supporting RMF functions and cybersecurity compliance.
- Strong knowledge of Federal, DoD, Intelligence Community, and industry cybersecurity standards.
- Significant experience with SDLC processes and developing technical documentation, manuals, SOPs, and best practices.
- Strong analytical, organizational, problem-solving, documentation, and briefing skills.
- Ability to prioritize and complete tasks with minimal direction in a high-pressure environment.
- Ability to communicate effectively with technical teams, customers, mission stakeholders, and all levels of management.
Certification Requirements
- Prior to starting, candidates must possess an applicable DoD cybersecurity certification that satisfies the contract's CSSP Infrastructure Support requirements.
Education
- Bachelor’s degree in Computer Science, Information Technology, Information Assurance, or a related field is desired.
- Master’s degree is preferred.
- Candidates without a degree should have 15+ years of relevant professional experience.
Skills
PythonAWSLinuxSQLCybersecuritySplunkRisk ManagementCompliance