Abile Group, Inc.-posted 3 months ago
Fort Meade, MD
11-50 employees

Abile Group has an exciting and challenging opportunity for a Lead Splunk Engineer Architect supporting a DoD Customer's Classified Network Services. The mission will include Operations, Compliance, Cyber Security, Customer Service, and Engineering. The right Lead Splunk Engineer Architect candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

  • Provides Splunk support for design, architecture, development, unit test, deployment, installation, configuration, integration, operation, and maintenance.
  • Redesigns an enterprise Splunk environment using industry practices along with cluster environments or multi-tenant environments.
  • Experience in the design and upgrade of Splunk in the cloud and on-premises environments to include architecting search head, indexer, universal forwarder, and heavy forwarder instances needed to service the expanding enterprise demand expected on the Splunk System as cross organizational use cases emerge.
  • Drives complex security focused Splunk deployments, including architecting, implementing, and integrating with a current or planned customer security and monitoring strategy to include advanced products like Enterprise Security.
  • Builds Splunk dashboards that take inputs from various data sources such as application logs, operating system logs, middleware logs, network feeds, etc.
  • Utilizes Splunk to develop data requirements, data catalog(s), data descriptions, data sources, and data formatting to ensure that security controls can be measured and managed across on-premises and cloud IT services.
  • Turns data into action with intelligent analytics and clear insights. Defines raw input requirements to support data models as well as final outputs required to ensure Department personnel can assess the security status of computing systems and produce readable, understandable summary reporting.
  • Inventories and assesses data sources and inputs and ensure this data is prioritized and properly formatted for Splunk ingest and report generation.
  • Builds Splunk dashboards that take inputs from vendor tools such as Tenable, Trellix, Cisco, Microsoft, etc.
  • Clearance Required: TS/SCI.
  • Degree and Years of Experience: 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD.
  • Five years of experience with planning, designing, deploying, and configuring Splunk in cloud, virtual, and physical environments.
  • Required Certification: Splunk Architect is required.
  • Splunk Certified Administrator certification required.
  • 8140/8570 IAT Level III certification required.
  • Expertise in Lookup Tables, CSV, and Summary Indexes.
  • Proven experience in a Splunk Architect role.
  • Strong understanding of Splunk architecture, components, and deployment options.
  • Proficiency in Splunk Search Processing Language (SPL) for creating complex search queries and reports.
  • Experience with Splunk data ingestion methods, including forwarders, HTTP Event Collector (HEC), and scripted inputs.
  • Solid understanding of IT infrastructure, including networking, operating systems, and security principles.
  • Excellent problem-solving skills and attention to detail.
  • Strong communication and collaboration abilities.
  • Experience with installing Enterprise Security, SOAR, and Qmulos.
  • Familiarity with Syslog servers.
  • System administrator.
  • Network administrator.
  • Experience with Linux and Windows.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service