Splunk Cloud Administrator

Gunnison Consulting GroupAtlanta, GA
5h$95,000 - $115,000Hybrid

About The Position

The Splunk Cloud Administrator will support cybersecurity operations for the CDC by designing, implementing, and managing Splunk Cloud and Splunk Enterprise environments across on premises, MSP, and multi cloud infrastructures. This role enables enterprise security monitoring, data integration, automation, and compliance activities for the CDC’s Cybersecurity Program Office (CSPO). Deploy, configure, and maintain Splunk Cloud and Splunk Enterprise across Linux, Windows, AWS, Azure, and container/serverless environments. Administer system upgrades, version control, and troubleshooting across cloud, physical, and virtual systems. Ensure reliable, secure Splunk operations supporting enterprise security functions. Integrate cybersecurity data from diverse tools (e.g., ExtraHop, Gigamon, BigFix, ForeScout, CrowdStrike). Build secure APIs/ETL pipelines and data flows between Splunk, ServiceNow, and Archer. Create dashboards, alerts, and datasets that enable threat detection, investigations, and compliance reporting. Provide Splunk-based orchestration and automation services. Develop integration requirements, diagrams, data mappings, and implementation plans. Collaborate with subject matter experts to support security automation initiatives. Operate CDM tools integrated with Splunk; maintain asset inventories and security agent coverage. Support vulnerability reporting and POA&M tracking. Configure cybersecurity tools to detect enterprise threats and support Zero Trust principles. Evaluate emerging technologies and advise operational teams on secure implementation. Apply patches per DHS/HHS timelines and follow change management standards. Conduct testing and restore failed systems within one hour. Provide possible after-hours support and notify stakeholders of service impacts. Produce system authorization documentation and maintain records of deployments and integrations. Conduct annual assessments and support security architecture development.

Requirements

  • Expert Splunk Cloud/Enterprise administration; strong SPL, API, ETL, Linux/Windows, AWS/Azure skills.
  • Knowledge of cybersecurity tools, databases, FISMA, vulnerability management, Zero Trust, CDM, and GRC platforms.
  • ServiceNow/Archer familiarity
  • Strong communication, documentation, analysis, and teamwork capabilities.
  • Splunk Cloud Certified Admin, or Splunk Certified Admin
  • B.S. in Cybersecurity, Computer Science, Information Technology, or similar area of study
  • Ability to obtain and maintain a Public Trust.

Nice To Haves

  • Federal or healthcare sector experience; CDC/HHS experience
  • NIST knowledge
  • CISSP certification
  • Security+ certification
  • M.S. in Cybersecurity, Computer Science, Information Technology, or similar area of study

Responsibilities

  • Deploy, configure, and maintain Splunk Cloud and Splunk Enterprise across Linux, Windows, AWS, Azure, and container/serverless environments.
  • Administer system upgrades, version control, and troubleshooting across cloud, physical, and virtual systems.
  • Ensure reliable, secure Splunk operations supporting enterprise security functions.
  • Integrate cybersecurity data from diverse tools (e.g., ExtraHop, Gigamon, BigFix, ForeScout, CrowdStrike).
  • Build secure APIs/ETL pipelines and data flows between Splunk, ServiceNow, and Archer.
  • Create dashboards, alerts, and datasets that enable threat detection, investigations, and compliance reporting.
  • Provide Splunk-based orchestration and automation services.
  • Develop integration requirements, diagrams, data mappings, and implementation plans.
  • Collaborate with subject matter experts to support security automation initiatives.
  • Operate CDM tools integrated with Splunk; maintain asset inventories and security agent coverage.
  • Support vulnerability reporting and POA&M tracking.
  • Configure cybersecurity tools to detect enterprise threats and support Zero Trust principles.
  • Evaluate emerging technologies and advise operational teams on secure implementation.
  • Apply patches per DHS/HHS timelines and follow change management standards.
  • Conduct testing and restore failed systems within one hour.
  • Provide possible after-hours support and notify stakeholders of service impacts.
  • Produce system authorization documentation and maintain records of deployments and integrations.
  • Conduct annual assessments and support security architecture development.

Benefits

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - $2,500/year!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service