Splunk Engineer - Mid
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations.The CBPSOCis responsible forthe overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed securityviolations.Leidoscurrently has a need for a Splunk Engineer for this highly visible cyber security program supporting Customs and Border Protection (CBP) security operations center(SOC).TheSplunk Engineer will support the full systemengineering life cycle, including requirements analysis, design, development,implementation, integration, test, and documentation. The Splunk Engineer will follow defined best practices and operational workflows., The Splunk Engineer will provide overall engineering, and administration in supportinga very largedistributed clustered Splunkenvironment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders, and Splunk Enterprise Security premium apps, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources intoSplunk, building dashboards, searches, reports, etc. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps. In addition, the Splunk engineer should be familiar with ansible or other automation tools.The Splunk Engineer will be a member of theEnterprise Splunk team, which falls under Cybersecurity Engineering, and will berequiredto interact withend users to gather requirements, perform troubleshooting, andprovide assistancewith the creation of Splunk search queries and dashboards. The Splunk Engineer may berequiredinteractwith senior management, as necessary.
Requirements
-
A minimum of aBachelor’sdegree with 8+ years’ experience in the Information Technology arena.
-
Additional Cyber Security Certifications and experience may be considered in lieu ofBachelor’sdegree.
-
A combination of 4+ Years experience in Linux, Splunk, Ansible, app interface development, using REST APIs, or other Cyber technologies.
-
Ability to followChange & Configuration Management,utilizingautomation tools, such as Git.
-
4+ years of experience in a Splunk roleworking in aSplunkclusteredenvironment, with experience in Splunk premium app management (Enterprise Security, ITSI).
-
Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
-
Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision.
-
Knowledge of Cloud Services such as AWS, Office365.
-
Understanding and usage of Regex.
-
Experience with scripting languages, such as Python, Bash, Visual Basic or PowerShell.
-
Understanding basic networking principles or Enterprise network design.
-
Possess baseline security certification to meet DoD 8570 at IAT II requirements, such as Security +.
Must have at least one of the following certifications:
-
SplunkEnterprise Security Certified Admin
-
Splunk IT Service Intelligence Certified Admin
-
Splunk Cloud Certified Admin
-
Splunk SOAR Certified Automation Developer
-
Splunk Certified Developer
-
Splunk Enterprise Certified Admin
-
Splunk Enterprise Certified Architect
-
Splunk Core Certified Consultant
Must have a current or be able to favorably pass a 5-year (BI) Background Investigation to join this program.
Preferred Qualifications
-
Prior experience in Splunk professional services role.
-
Possess certifications in Splunk premium app, such as Enterprise Security, ITSI, UBA.
-
Splunk Certified Developer certification.
-
Experience in automating Splunk Deployments and orchestration within a Cloud environment.
-
Experience with FISMA Systems requirements.
-
Experience with Confluence, JIRA, ServiceNow.
-
Cribl CCOE User certification.
-
Knowledge/experience with CBP/DHS
Benefits & conditions
Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
About the company
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?
Fully Remote Software Engineer Jobs
Best Paying Jobs in Technology