Logo
ENS Solutions, LLC

Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC, College Park, Maryland, us, 20741

Save Job

Overview You will work with an expert team focused on implementing and operating next-generation security solutions for government and commercial clients. You'll use Splunk and integrate it with other tools like HBSS, Enterprise Security Manager (ESM), Network Security Manager (NSM), NetFlow, and/or Intrusion Detection Systems (IDS) to monitor, detect, and analyze threats. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies and apply in-depth defense strategies for large and complex networks to rapidly identify vulnerabilities and threats, prioritizing response actions, including developing effective countermeasures. You'll support the risk management and security compliance of specified cyber security tools. You'll apply thought leadership to solving complex security challenges in a highly collaborative and innovative work environment.

Responsibilities

Evaluate, implement, and operate security tools and technologies to monitor, detect, and analyze threats.

Prioritize response actions and develop effective countermeasures for vulnerabilities and threats on large, complex networks.

Support risk management and security compliance of specified cyber security tools.

Collaborate in a team environment to solve complex security challenges with innovative approaches.

Qualifications

3+ years of experience utilizing Splunk Enterprise.

Experience deploying, configuring, and performing functional testing and data validation in a Splunk environment.

Experience with Splunk systems administration, including installation, configuration, monitoring, upgrades, and troubleshooting in Windows and Linux Server environments.

Experience creating custom dashboards, writing queries, generating reports, and setting up alerts and notifications.

Familiarity with DoD Risk Management Framework.

Top Secret/SCI clearance with the ability to obtain a Counter-Intelligence polygraph.

Education/experience combination: HS diploma or GED with 7+ years IT project experience, Associate's with 5+ years, or Bachelor's with 3+ years.

DoD 8570 IAT Level II Certification (e.g., CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP).

Ability to obtain DoD 8570.01-M Cybersecurity Service Provider - Infrastructure Support Certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date.

Optional Qualifications

Ability to ingest and parse logs within Splunk.

Experience with fields abstraction, data modeling in Splunk, workflows and drilldown queries, and administering Splunk in distributed deployments.

Experience with site surveys, data gathering, and analysis for deploying security tools.

Splunk Certified Power User or other advanced Splunk Certification.

Experience with DevSecOps and Elasticsearch, Logstash & Kibana (ELK).

Excellent oral and written communication skills, including presenting complex ideas to clients and internal staff.

Strong problem-solving skills.

Benefits

Free Platinum-Level Medical/Dental/Vision coverage, 100% paid by ENS.

401k contribution from Day 1.

PTO + 11 Paid Federal Holidays.

Long & Short Term Disability Insurance.

Group Term Life Insurance.

Tuition, Certification & Professional Development Assistance.

Workers' Compensation.

Relocation Assistance.

#J-18808-Ljbffr