Jr. Splunk Engineer
Role details
Job location
Tech stack
Job description
PRISM is seeking a Jr Splunk Engineer to support a mission-critical program. In this role, you will be responsible for providing Junior Splunk analysis, maintenance, and reporting support to multiple Splunk distributed enterprise environments (PROD, TEST, POC)., Defining security, utilization, and performance requirements for local and wide area networks. Implement solutions that align with the Government's security / monitoring systems and requirements. Proficiency in the SPLUNK platform, familiar with Ansible, Python, and PowerShell scripting, Internet Proxy Logs, RSA, Windows Active Directory, Windows Servers, Red Hat Enterprise Linux Servers, and capacity planning in Windows/ Linux environments. Perform daily administrative tasks to manage Splunk datasets and storage utilization. Monitoring automated backup tasks, manually backing up data if necessary, monitoring storage utilization on Splunk servers in all environments as well as network attached storage. Maintain Splunk Knowledgebase by updating existing and creating new KB articles as identified by the team. Create and update Splunk resources including saved searches, visualizations, alerts, dashboards and any other ad hoc deliverables as needed. Interface with user community and provide first level of support to troubleshoot issues or assist with any other Splunk requirements. Coordinate with, accept tasking from, accept guidance from, and collaborate on priorities with Senior Splunk engineer / Task lead. Participate in periodic stand-up task meetings. Create Splunk reports and dashboards as identified as needed based on enterprise customer requirements or internal team needs. Assist in creating, updating, and documenting Ansible playbooks (scripts) used to automate tasks and workflows (groups of tasks) within the Splunk environments. Manage Splunk lookups by verifying that automated jobs are updating lookup tables properly as well making adhoc changes as necessary. Monitor, administer and maintain accessibility to Splunk components including search heads, indexers, deployers, cluster masters, forwarders and syslog servers for continuous production environment uptime Manage and secure RHEL and Windows servers for Splunk platform including patches and access controls. Assist team with reviewing/assessing/implementing new data sources, ie: syslog, scripted input, db inputs Working with IT Managers to validate data and provide training on new dashboard enhancements Assist with maintaining existing PowerShell / Python / C# scripts and creating new scripts as needed Assist with integrating various data sets into Splunk and creating new dashboards to ensure the confidentiality, integrity, security and availability of the WAN Provide a weekly Progress/Exceptions Report to include a list of tasks assigned, completed, and pending.
Requirements
Experience in defining security, utilization, and performance requirements for local and wide area networks Proficient in implementing solutions that align with the Government's security / monitoring systems and requirements Proficient in the SPLUNK platform, familiar with Ansible, Python, and PowerShell scripting, Internet Proxy Logs, RSA, Windows Active Directory, Windows Servers, Red Hat Enterprise Linux Servers, and capacity planning in Windows/ Linux environments.