Splunk Cloud Administrator

Gunnison Consulting GroupAtlanta, GA
16d$95,000 - $115,000

About The Position

The Splunk Cloud Administrator will support cybersecurity operations for the CDC by designing, implementing, and managing Splunk Cloud and Splunk Enterprise environments across on-premises, MSP, and multi-cloud infrastructures. This role enables enterprise security monitoring, data integration, automation, and compliance activities for the CDC’s Cybersecurity Program Office (CSPO).

Requirements

  • Splunk Cloud Certified Administrator
  • Expert Splunk Cloud/Enterprise administration; strong SPL, API, ETL, Linux/Windows, AWS/Azure skills.
  • Knowledge of cybersecurity tools, databases, FISMA, vulnerability management, Zero Trust, CDM, and GRC platforms.
  • ServiceNow/Archer familiarity
  • Strong communication, documentation, analysis, and teamwork capabilities.
  • B.S. in Cybersecurity, Computer Science, Information Technology, or similar area of study required.
  • Ability to obtain and maintain a Public Trust.

Nice To Haves

  • Federal or healthcare sector experience; CDC/HHS experience
  • NIST knowledge
  • Experience with Cribl or Armis
  • Relevant cybersecurity certification (CISSP, CompTIA Security+, etc.)
  • M.S. in Cybersecurity, Computer Science, Information Technology, or similar area of study preferred.

Responsibilities

  • Write and optimize advanced SPL queries for monitoring, reporting, and troubleshooting.
  • Manage data ingestion, indexing, and forwarding from cloud, server, application, and endpoint sources.
  • Configure and support Splunk forwarders, Syslog-NG, Cribl, AWS Lambda, and Azure Function Apps for reliable data intake.
  • Create dashboards, visualizations, reports, and alerts for both technical and business users.
  • Automate operational tasks and data processes using Python, Bash, and PowerShell.
  • Support Splunk environments in both self-hosted and Splunk GovCloud deployments.
  • Integrate Splunk with enterprise platforms including Archer, ServiceNow, Azure, and AWS.
  • Troubleshoot platform, infrastructure, networking, and security-related issues impacting data visibility and performance.
  • Apply Splunk AI Toolkit for use cases such as anomaly detection, forecasting, clustering, and predictive analytics.
  • Support secure implementation and evaluation of emerging Splunk capabilities such as the Splunk MCP Server.
  • Partner with internal teams to onboard data sources, improve workflows, and deliver scalable observability solutions.
  • Contribute to monitoring and visibility for AI application stacks, including LLMs and related infrastructure, when needed.

Benefits

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - $2,500/year!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service