Job Description
DELMOCK TECHNOLOGIES INC’S, Senior Recruiter Stan Blackwell (sblackwell@delmock.com / 410-218-0900) would love to speak with you regarding the following position: SPLUNK ARCHITECT, in LAUREL, MD.
WHAT YOU WILL DO
We are seeking a candidate who can deploy and maintain the backend architecture and developing content for a complex and growing Splunk infrastructure. This includes use cases for Dashboards, Reports, Alerts, as well as Splunk Apps, Technology Add-ons, Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The candidate will need to participate in the operation of Splunk and Splunk ES, logging infrastructure, Windows and Linux servers, and backups as they support life-cycle management of the Splunk platform to including coordination and planning of upgrades, new deployments, and maintaining current operational data flows. Splunk Engineer will support:
- Preparation activities to include a use case workshop, requirements gathering and capacity planning
- Splunk Core and Splunk ES Architecture Deployment
- Data onboarding and normalization
- Use case development and data visualization
- Tuning of architecture, data streams, and use cases
WHO YOU WILL WORK WITH
Works with other team members.
WHO YOU ARE
A Splunk Architect that can deploy and maintain the backend architecture and developing content for a complex and growing Splunk infrastructure.
Our minimum requirements for this role:
REQUIRED
- U.S. Citizenship U.S. Permanent Resident
- Bachelor's Degree in Information Technology, Cyber Security, Computer Science, Computer Engineering, or Electrical Engineering
- Experience in system integration including the design, development, enhancement of cyber systems
- Experience with Splunk operations and maintenance
- Must possess strong written and verbal communication skills and must be capable of the understanding, documenting, communicating and presenting technical issues in a non-technical manner to audiences with varying degrees of technical expertise
- Must have demonstrated ability to build and implement event correlation rules, logic, and content in the security information and event management system with specific experience in the Splunk platform
- Must have demonstrated ability to tune the SIEM event correlation rules and logic to filter out security events associated with known and well-established network behavior, known false positives and/or known errors
- Must have experience maintaining an event schema with customized security severity criteria
- Must have experience creating scheduled and ad-hoc reporting with Splunk
- Must possess a thorough and in-depth understanding of SEIM technologies and event collection mechanisms in the Windows and Linux operating environments
- Demonstrated experience with Extraction, Transformation, and loading of data including skills in SPL and Regex
CURRENT EMPLOYEE TESTIMONIES
Best work experience to date. The salary and benefits are excellent, while the company cares about its employees. It’s rare when the CEO knows each employee personally.
ABOUT YOUR NEW COMPANY
Employment with DTI means growth. DTI is a Baltimore-based certified HUBZone business providing complex mission-critical IT and Health solutions. Valuing Ethics Expertise, Technology and Delivery of Superior Service.