Splunk Administrator - Cyber Security Analyst Advisor

MacDill AFB, Florida


Employer: General Dynamics Corporation
Industry: Information Technology
Salary: Competitive
Job type: Full-Time, Part-Time

Responsibilities for this Position
Location: USA FL MacDill AFB - 7701 Tampa Point Blvd (FLC097)
Full Part/Time: Full time
Job Req: RQ169864

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret/SCI

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Suitability:

Public Trust/Other Required:

Job Family:
Cyber Security

Job Qualifications:

Skills:
Cyber Defense, Cyber Operations, Splunk
Certifications:

Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description:

Title: Splunk Administrator - Cyber Security Analyst Advisor

Clearance Needed: TS/SCI
Location: USA FL MacDill AFB - 7701 Tampa Point Blvd (FLC097)


Please take this opportunity to join one of GDIT's fastest long-standing growing programs! US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) is a cutting edge program supporting DoD intelligence information sharing on current and emerging global threats to mission and coalition partners and emerging nations. With an internationally dispersed team supporting each combatant command, the US BICES-X team is in direct support of the war fighter and their missions. We are seeking a creative and driven professional with a passion for solving real world issues on a cross-functional, fast paced team.

As part of the Defensive Cyber Operations Team, you'll be charged with maintaining the Cyber Security Posture for Enterprise data centers, workstations, and remote locations across the globe.
  • Performs Defensive Cyber Operations (DCO) activities (formally known as Cyber Network Defense) for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
  • Ensure the continuity and smooth functionality of the Splunk service, its associated components, and its integrations with other services, Operations and Sustainment.
  • Design and implement solutions to address business problems, understanding the Splunk architecture requirements for scalability, security, performance, and cost-efficiency.
  • Ensure the security of the Splunk environment by performing proactive health checks and keeping abreast of new threats and vulnerabilities that may affect them.
  • Remain current and up to date with emerging technologies, organization requirements and enhancements & develop proposals for changes that may be required.
  • Develop best practices, standards, and architectural principles for the Splunk service.
  • Assist/engage other system owners and project managers that have integration requirements with the Splunk.
  • Assist/engage other engineering teams for problem determination of incidents.
  • This position will be working within our DCO environment providing but not limited to; Implementation and Administration of Security Ops, SPLUNK, SYSLOG, ACAS, HBSS, and security related activities to secure and harden systems.
  • Utilize available resources to conduct Cybersecurity activities, and report to senior GDIT and government personnel on overall program security posture.
  • Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Solaris, Linux, Windows, and associated network operating systems.
  • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
  • Provides guidance and work leadership to less-experienced technical staff members.
  • Maintains current knowledge of relevant technology as assigned.
  • Participates in special projects as required.
Required Qualifications:
  • 8+ years of technical experience required.
  • BA/BS required - may substitute additional years of experience
  • Must possess and maintain a TS/SCI Clearance.
  • SPLUNK Core Certified Power User
  • Experience with infrastructure including but not limited to: data center operations, server hardware, operating systems (Windows, Linux), web servers, databases, virtualization (VMware), networking, storage, monitoring, etc.
  • May be required to work evening, weekend, and holiday hours as required.
  • Must meet DoD 8570 requirements and be eligible for IAT level II & CSSP-IS access upon hire for positions with elevated privileges and must obtain ITIL V4 Foundation within six months of hire.
  • Depending on job assignment, additional specific certifications may be required.
Preferred Qualifications:
  • The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
  • Extensive experience and knowledge of Splunk architecture, distributed components (indexer clusters, forwarders, search head clusters, deployment servers, dashboards etc).
  • Strong knowledge of Splunk Enterprise Security at administration and use case level.
  • Deep understanding of:
    • Splunk language (SPL)
    • Intermediate Python or PowerShell scripting a must
    • CSS, XML, macros, and JavaScript.
    • External systems management products & feeds, particularly, but not limited to the M365 security portfolio.
    • Optimised data architectures & data analytics.
    • WANs and LANs and TCP/IP.
  • Must have a thorough (advanced to expert) understanding of IT security and implementation of security related guidelines and impact on IT infrastructures.
  • Problem solving abilities across enterprise multiple technology environments with complex integrations.
  • Strong time management skills.
  • Strong verbal and written communication skills; must be able to communicate effectively with a wide variety of audiences, both business and technical.
  • Work collaboratively and cooperatively with diverse geographical and cultural groups.
  • The work is typically performed in an office environment, which requires normal safety precautions; work may require some physical effort in the handling of light materials, boxes or equipment.
Scheduled Weekly Hours:
40

Travel Required:
None

Telecommuting Options:
Onsite

Work Location:
USA FL MacDill AFB

Additional Work Locations:

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day. We create opportunities for our people to lead and learn simultaneously. From securing our nation's most sensitive systems, to enabling digital transformation and cloud adoption, our people are the ones who make change real.

GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.

PI237939907

Back To Search Results GDIT supports and secures some of the most complex government, defense, and intelligence projects across the country.

Created: 2024-04-19
Reference: RQ169864
Country: United States
State: Florida
City: MacDill AFB