Cyber Defense Engineering Architecture Senior Analyst
Cyber Security Cyber Risk Posted: 10-Oct-2024
Alexandria, Virginia, United States
Arlington, Virginia, United States
Mclean, Virginia, United States
Rosslyn, Virginia, United States
Work you'll do
- Partner with development and operations teams to develop practical automation solutions and custom modules.
- Co-lead team initiatives to continuously refine our deployment practices for improved reliability, repeatability, and security. Creating plans and collaborating with other GEMS Engineering team members, while coordinating with development and business teams.
- Develop requirements for data ingestion methods based on input from stakeholders/leadership.
- Clearly document and diagram deployment-specific aspects of architectures and environments, working closely with various teams to create application runbooks, playbooks, and knowledge base documents.
- Troubleshoot issues in production and other environments, applying debugging and problem-solving techniques (e.g., log analysis, non-invasive tests).
- Suggest deployment patterns & practices improvements based on learnings from past deployments and production issues, collaborate with GEMS Engineering team members to implement these.
- After hours on-call support occasionally required.
The team
Qualifications
- Minimum of 2 years Splunk engineering experience
- Minimum of 1 year managing other Splunk engineers or projects
- Strong understanding of Cloud Services – Azure, AWS
- Strong understanding of Splunk data onboarding including Splunk App/TA configuration and CIM validation
- Universal/Heavy Forwarder configuration experience, including encryption and compression settings
- Experience working with a strict change control process utilizing tools such as Azure DevOps
- Management/deployment experience with large scale/distributed Splunk environments
- A solid understanding of Windows and Linux administration utilizing Command Line Interface (CLI)
- Knowledge of networking, firewalls, load balancers etc.
- Demonstrate understanding of common enterprise applications (especially in the area of security)
- Knowledge of best practices for IT operations in an always-on, always-available service model
- Bachelor’s degree in Computer Science, Computer Engineering, Finance, Mathematics, Business Information Systems or other bachelor’s degree combined with relevant experience and accomplishments.
- One or more of the following; Splunk Certified Admin, Splunk Certified Architect, Splunk Certified Consultant
- Experience with Cribl administration and data onboaring
- Experience in work in large global organizations