Splunk Cloud Administrator

Gunnison Consulting GroupAtlanta, GA
1d

About The Position

The Splunk Cloud Administrator will support cybersecurity operations for the CDC by designing, implementing, and managing Splunk Cloud and Splunk Enterprise environments across on-premises, MSP, and multi-cloud infrastructures. This role enables enterprise security monitoring, data integration, automation, and compliance activities for the CDC’s Cybersecurity Program Office (CSPO).

Requirements

  • Splunk Cloud Certified Administrator
  • Expert Splunk Cloud/Enterprise administration; strong SPL, API, ETL, Linux/Windows, AWS/Azure skills.
  • Knowledge of cybersecurity tools, databases, FISMA, vulnerability management, Zero Trust, CDM, and GRC platforms.
  • ServiceNow/Archer familiarity
  • Strong communication, documentation, analysis, and teamwork capabilities.

Nice To Haves

  • Federal or healthcare sector experience; CDC/HHS experience
  • NIST knowledge
  • Experience with Cribl or Armis
  • Relevant cybersecurity certification (CISSP, CompTIA Security+, etc.)

Responsibilities

  • Write and optimize advanced SPL queries for monitoring, reporting, and troubleshooting.
  • Manage data ingestion, indexing, and forwarding from cloud, server, application, and endpoint sources.
  • Configure and support Splunk forwarders, Syslog-NG, Cribl, AWS Lambda, and Azure Function Apps for reliable data intake.
  • Create dashboards, visualizations, reports, and alerts for both technical and business users.
  • Automate operational tasks and data processes using Python, Bash, and PowerShell.
  • Support Splunk environments in both self-hosted and Splunk GovCloud deployments.
  • Integrate Splunk with enterprise platforms including Archer, ServiceNow, Azure, and AWS.
  • Troubleshoot platform, infrastructure, networking, and security-related issues impacting data visibility and performance.
  • Apply Splunk AI Toolkit for use cases such as anomaly detection, forecasting, clustering, and predictive analytics.
  • Support secure implementation and evaluation of emerging Splunk capabilities such as the Splunk MCP Server.
  • Partner with internal teams to onboard data sources, improve workflows, and deliver scalable observability solutions.
  • Contribute to monitoring and visibility for AI application stacks, including LLMs and related infrastructure, when needed.

Benefits

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - $2,500/year!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service