Splunk / Elastic Team Lead

LeidosAlexandria, VA
11hOnsite

About The Position

Leidos is seeing a Splunk/Elastic Team Lead on our GSMO II IDIQ contract’s DISA J-6 Cyber Security Task Order in Alexandria, VA. DISA J-6 provides a full range of IT products, services, and solutions and customer services to the Office of the Secretary of Defense (OSD), Chairman of the Joint Chiefs of Staff (CJCS) and the Joint Staff (JS), Director of Administration (DA), Pentagon Force Protection Agency (PFPA), Washington Headquarters Services (WHS), and other OSD offices for them to meet mission and business requirements. Through the DISA J-6 Cyber Security program, DISA J-6 performs a wide variety of services and functions required to secure the information security posture for DoD services. An active Secret security clearance is required prior to start and this role will be based onsite in the Arlington, VA area.

Requirements

  • Bachelor's degree and 8+ years of prior relevant experience. Additional experience may be considered in lieu of degree.
  • Active Secret security clearance is required prior to start.
  • DoD 8570 IAM II certification
  • Splunk Core Certified Power User, Equivalent certification or higher
  • Elastic Certified Analyst, Equivalent certification or higher
  • Excellent written and oral communications skills and be able to appropriately present highly technical material to both technical and non-technical audiences

Nice To Haves

  • Prior experience as a network intrusion analyst or Security Operations Center analyst.
  • Experience configuring and maintaining the tool in a multi-tenant environment
  • Experience with one or more Security tools: Qmulos ACAS HBSS Tanium

Responsibilities

  • Design efficient and reusable reports and dashboards to integrate multiple mission applications’ health, performance and operational data systems into Splunk/Elastic
  • Direct and monitor reporting in Splunk/Elastic dashboards to reflect compliance status of DISA J-6 with all directed information assurance vulnerability alerts and bulletins, Computer Tasking Orders, and other compulsory cyber security directives.
  • Create front-end automated data visualization services using Splunk/Elastic
  • Create viewable Splunk/Elastic dashboards to provide visibility into ingested log data
  • Create alerts that trigger/activate on configured setting to deploy or sends a note/email/attachments to a particulate destination email or groups
  • Create security rules (alerts) that trigger on anomalous activities or threat detections
  • Utilize Qmulos, Splunk, Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), and Tanium to assess/validate/monitor the security controls and security posture of the enterprise and system level in order to support on-going authorization.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service