Splunk Administrator (Level 3)
G2IT is seeking an experienced Splunk Administrator (Level 3) to support enterprise cybersecurity, monitoring, and data analytics environments. The ideal candidate will have extensive hands-on experience administering and optimizing Splunk environments, supporting Cyber Network Defense (CND) operations, and working within DoD or Intelligence Community environments.
Key Responsibilities
- Install, integrate, configure, administer, maintain, monitor, troubleshoot, and optimize Splunk environments.
- Support Splunk Enterprise and advanced applications, including Enterprise Security (ES), SOAR, UEBA, and IT Service Intelligence (ITSI).
- Install and manage Splunk Technical Add-ons (TAs), Apps, and Universal Forwarders.
- Develop SPL queries, dashboards, reports, alerts, and other monitoring capabilities.
- Perform log management, ingestion, parsing, normalization, and analysis.
- Create REGEX parsing and XML presentations of log data.
- Maintain Splunk Common Information Model (CIM) compliance and perform automated and manual data mapping.
- Utilize Python scripting to automate Linux and Splunk administration tasks.
- Work with Splunk DB Connect, SQL, and database integrations to collect and analyze log data.
- Create, install, and maintain encryption keys used to secure communication channels.
- Perform Risk Management Framework (RMF) functions associated with Splunk environments.
- Support AWS resources and Red Hat Enterprise Linux environments.
- Troubleshoot LAN/WAN, networking protocols, ports, services, file systems, and Windows/Unix/Linux infrastructure.
- Develop technical documentation, SOPs, best practices, presentations, and cybersecurity guidance.
- Support System/Software Development Life Cycle (SDLC) processes.
- Communicate complex cybersecurity and technical issues to management, mission stakeholders, and customers.
Required Qualifications
- Must hold an active Top Secret (TS) security clearance and be eligible for TS/SCI access.
- 10+ years of professional experience with LAN/WAN technologies, networking protocols, file systems, ports, services, and commands within Windows and Unix/Linux environments.
- 8+ years of concentrated experience within the Cyber Network Defense (CND) discipline.
- 6+ years of professional hands-on experience with Splunk administration, integration, configuration, maintenance, and optimization.
- Expert-level knowledge of Splunk Enterprise and Splunk applications, including ES, SOAR, UEBA, and ITSI.
- Extensive experience with Splunk Add-ons, Apps, Technical Add-ons (TAs), and Universal Forwarders.
- Strong experience creating SPL queries, dashboards, reports, and alerts.
- Experience with REGEX parsing and XML presentation of log data.
- Experience using Python to automate Linux and Splunk administrative tasks.
- Experience with Splunk DB Connect, SQL, and database log collection.
- Experience with Splunk Common Information Model (CIM) compliance and data mapping.
- Experience creating and managing encryption keys for secure communications.
- Experience administering and managing AWS and Red Hat Enterprise Linux environments.
- Significant experience supporting RMF functions and cybersecurity compliance.
- Strong knowledge of Federal, DoD, Intelligence Community, and industry cybersecurity standards.
- Significant experience with SDLC processes and developing technical documentation, manuals, SOPs, and best practices.
- Strong analytical, organizational, problem-solving, documentation, and briefing skills.
- Ability to prioritize and complete tasks with minimal direction in a high-pressure environment.
- Ability to communicate effectively with technical teams, customers, mission stakeholders, and all levels of management.
Certification Requirements
- Prior to starting, candidates must possess an applicable DoD cybersecurity certification that satisfies the contract's CSSP Infrastructure Support requirements.
Education
- Bachelor’s degree in Computer Science, Information Technology, Information Assurance, or a related field is desired.
- Master’s degree is preferred.
- Candidates without a degree should have 15+ years of relevant professional experience.