Splunk Architect
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
About the Disruptive Team
Welcome to Disruptive Solutions, where innovation meets dedication in the realm of cybersecurity and technology. As a dynamic SDVOSB, we pride ourselves on fostering a culture that transcends traditional boundaries, bringing cutting-edge cyber technology from the industry to the government. Our commitment to harnessing the power of AI and machine learning is matched only by our focus on people—the heart of our success. Join us in our mission to 'Secure the Future' as we empower you to shape transformative solutions that drive efficiency and meaningful outcomes for our clients. Together, let’s redefine what’s possible in cybersecurity and make a lasting impact.
In this role, you will:
Develop and implement Splunk security solutions in alignment with security strategy. Maintain awareness of market and technology trends to bring best of breed solutions to the client. Apply consulting or technical expertise as well as full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction and mentor or supervise team members, if needed.
Requirements:
Possess an active Public Trust
10+ years experience with system integration, including the design, development, and enhancement of cyber systems
4+ years of experience with Splunk operations and maintenance
Experience with maintaining an event schema using customized security severity criteria
Experience with creating scheduled and ad-hoc reporting using Splunk
Experience with extraction, transformation, and loading of data, including SPL and Regex
Knowledge of SIEM technologies and event collection mechanisms in Windows and Linux operating environments
Ability to build and implement event correlation rules, logic, and content in the security information and event management system in the Splunk platform
Ability to obtain a security clearance
BA or BS degree
The ideal candidate will be based in the Northern Virginia/Washington DC area
You will be working remote
If you have any of these skills it will help you to excel in this role:
Experience with a cloud-based Splunk deployment
Experience with supporting a Security Operation Center’s Splunk deployment
Experience as a security engineer or security analyst
Ability to tune SIEM event correlation rules and logic to filter out security events associated with known and well established network behavior, known false positives, or known errors
Possession of excellent oral and written communication skills, including, understanding, documenting, communicating, and presenting technical issues in a non-technical manner to audiences with varying degrees of technical expertise
Possession of excellent problem-solving skills
BA or BS degree in Science, Technology, Engineering, or Mathematics (STEM)
Splunk Architect-level or above certification
Disruptive Solutions is committed to the principles of equal employment. We are committed to complying with all federal, state, and local laws providing equal employment opportunities, and all other employment laws and regulations. It is our intent to maintain a work environment that is free of harassment, discrimination, or retaliation because of age, race, color, national origin, ancestry, religion, sex, sexual orientation (including transgender status, gender identity or expression), pregnancy (including childbirth, lactation, and related medical conditions), reproductive health decisions, marital status, personal appearance, matriculation, political affiliation, credit information, employment status, physical or mental disability, genetic information (including testing and characteristics), veteran status, uniformed servicemember status, status as a victim or family member of a victim of domestic violence, a sexual offense, or stalking, homeless status, or any other status protected by federal, state, or local laws.