Leidos currently has a need for a Sr Splunk Engineer for a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis, application development, and a 24x7x365 support staff. Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP) and is responsible for directing and coordinating detection and response activities performed by each Component SOC. Direction and coordination are achieved through a new shared DHS incident tracking system and other means of coordination and communication. The selected candidate will provide overall engineering and design support for a very large distributed Splunk environment consisting of heavy forwarders, indexers, and search head servers, spanning security, performance, and operational roles. The Sr Splunk Engineer will support the full system engineering life-cycle, including requirements analysis, design, development, integration, test, documentation, and implementation following defined best practices and operational workflows.
The candidate should be familiar with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Sr Splunk Engineer should be familiar with a Linux environment, editing and maintaining Splunk configuration files and apps.
The Sr Splunk Engineer will work with other Cybersecurity Engineering team members and will be required to interact with end users to gather requirements, perform troubleshooting, and provide assistance with the creation of Splunk search queries and dashboards. The Sr Splunk Engineer will be required interact with senior management, as necessary.
A minimum of a Bachelor's degree coupled with 12+ years' experience in the Information Technology arena or Masters with 10 - 13 years of prior relevant experience; and Splunk Core Certified Power User certification is preferred. A Splunk Core Certified Power User has a basic understanding of SPL searching and reporting commands and can create knowledge objects, use field aliases and calculated fields, create tags and event types, use macros, create workflow actions and data models, and normalize data with the Common Information Model in either the Splunk Enterprise or Splunk Cloud platforms. This foundational, entry‑level certification demonstrates an individual's foundational competence of Splunk's core software.
4+ years of experience in a senior Splunk role
3+ Years experience in Linux and SQL/ODBC interfaces
2+ Years experience in app interface development, using REST API's
Previous project management experience.
ITIL Change & Configuration Management
- Experience in SQL
- Experience in other systems and network management products.
Current or former completed Splunk training