Share this job
SPLUNK Administrator - 1838941
Annapolis Junction, MD
Apply for this job

Computer Technologies Consultants (CTC, Inc.) is seeking a SPLUNK Administrator to provide support on a US Navy Enterprise Networks program in Annapolis Junction, MD. 


With offices in Washington DC and San Diego, CA, CTC is a leading technology company providing lifecycle IT, data analytics, cloud managed hosting services, agile software development, DevOps, Test Automation, Cyber Security, and infrastructure solutions. Additionally, we provide Professional Talent Acquisition Services as we proudly support the unique needs of U.S. Defense, Intelligence, and Federal Civilian agencies as well as Fortune 1000 companies.


Why Should You Be Interested?

  • Full-time position
  • Competitive pay and comprehensive benefits
  • Certified Small Business with room for growth
  • Long term and stable contract


Position Title: SPLUNK Administrator

Position Location: This position is onsite in Annapolis Junction, MD.


Description: We are seeking a career level engineer to maintain and enhance the existing Splunk infrastructure in the enterprise. Further projects will involve the implementation of Splunk Enterprise Security (ES) and Security Orchestration, Automation, and Response (SOAR) and other vendor solutions.


Daily Responsibilities:                                 

  • Implements, tests, and operates advanced software security techniques in compliance with technical reference architecture.
  • Performs on-going security testing and code review to improve software security.
  • Troubleshoots and debugs issues that arise.
  • Provides engineering designs for new software solutions to help mitigate security vulnerabilities.
  • Contributes to all levels of the architecture and maintains technical documentation.
  • Consults team members on secure coding practices. Develops a familiarity with new tools and best practices.
  • Designing, implementing, and maintaining SIEM and SOAR solutions.
  • Design and implement threat detection, automate incident response processes, integration of various security tools with SIEM and SOAR platforms via APIs
  • Maintain SIEM applications to collect and aggregate IDS and IPS data from network sensors, raw data from collection agents, firewalls, proxy servers, DLP, antivirus, vulnerability scanner elements, and other security-relevant devices.
  • Utilize expertise in Splunk "Search" language, Splunk Dashboards, Reports, Lookup Tables, and Summary Indexes. Build Splunk dashboards that take inputs from various data sources such as application logs / operating system logs / middleware logs / network feeds etc. and identify / highlight anomalous activities on the dashboards by their severity levels.
  • Perform troubleshooting and provide assistance with the creation of Splunk search queries and dashboards.


Qualifications

  • Bachelor's (or equivalent) with 2-4 yrs of experience, or a Master's and 0-2 yrs of experience.
  • Requires experience with importing data in Splunk from various sources: endpoint security, network security (Firewalls, IPS/IDS, DNS, Proxy, etc.), data and application security, cloud security and technologies.
  • Requires experience with performing systems administration, including performing installation, configuration, monitoring system performance and availability, upgrades, and troubleshooting of Splunk.
  • Requires experience with designing, implementing, configuring, operating, or testing IT systems or security infrastructure.
  • Requires experience building dashboards highlighting the key trends of the data.
  • Requires proficiency within a Windows and Linux environment, editing and maintaining Splunk configuration files and apps.
  • Experience in working in a Splunk clustered environment supporting SOC or NOC environment required.
  • Experience with virtualization technologies required.
  • Career level with a complete understanding and wide application of technical principles, theories and concepts. Working under only general direction, provides technical solutions to a wide range of difficult problems. Independently determines and develops approach to solutions.


Required Certifications:

  • Splunk Enterprise Certified Architect, Splunk Certified Admin
  • DoD 8570 Level 3 Certification


Required Clearance:

  • Must possess an active TSI clearance with SCI eligibility.


Pay Information

Full-Time Salary Range: $115k - $130k

Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.


Benefits/Perks

  • 401(k) matching
  • Accident and Hospital Indemnity Insurance
  • Dental Insurance
  • Disability Insurance
  • Employee Referral Bonus Program
  • Employee Assistance Plan
  • Flexible spending account
  • Health insurance
  • Life insurance (Term and Universal Life w/Long Term Care benefits)
  • Paid time off (Vacation, Sick leave, and 11 Federal Holidays)
  • Professional development assistance/Tuition reimbursement Program
  • Profit Sharing Retirement Program
  • Vision insurance


Computer Technologies Consultants, Inc. is an Equal Opportunity Employer that provides employment opportunities for all qualified applicants without regard to race, color, religion, gender identity and/or expression, sexual orientation, age, mental or sensory differing abilities, protected veteran status, sex, national origin, or any other characteristic protected by applicable law. Computer Technologies Consultants, Inc. is devoted to diversity, equity, and inclusion.

Apply for this job
Powered by