Join our talent network

Job #: R-00011719
Location: CHANTILLY, VA
Category: Cyber Security
Schedule (FT/PT): Full time
Travel Required: No
Shift: Day
Potential for Telework: No
Clearance Required: Top Secret/SCI with Polygraph
Referral Eligibility: Eligible
Group: Intelligence

Job Description:

The candidate will act as the senior support person for the Splunk team (currently transitioning from ArcSight to Splunk). Candidate must have the ability to configure and support ArcSight and Splunk. Must have proven experience and ability to leverage CND analyst toolsets to detect and respond to IT security incidents. The candidate will be responsible for operating, maintaining, and monitoring a Splunk SIEM installation at a 24/7 operations center. The candidate is responsible for Linux performance tuning & troubleshooting, identifying and resolving contention in CPU, memory, networking, disk I/O, etc.

In this role, the Cyber Security Engineer will:
  • Assist with transition activities from ArcSight to Splunk
  • Upgrade/update all Splunk components as required (Loggers, Connectors, ESM).
  • On-board new event sources by obtaining access to the logs, installing the software, and then tuning/adjusting the connector;
  • Monitor and tune of all ESM components for performance;
  • Assist with analyst activity by providing reports, writing queries, running searches, fixing broken content, etc;
  • Investigate any reported problems and determine the root cause;
  • Create documentation of standard procedures, system configurations, etc.;
  • Configure the tools to work with Syslog, File and Database collection of events.
  • Create and edit content to both monitor and alert on security incidents;
  • Provide guidance to both internal and external Customer issues and supporting tickets; and,
  • Provide Tier 2/3 troubleshooting for Splunk issues, either within the tool or as part of an integrated team of professionals addressing larger issues


Required Qualifications
  • Bachelor's degree and 10+ years' experience. Additional experience in lieu of degree.
  • 8+ years of experience in cyber security
  • Demonstrated expertise in Splunk and/or ArcSight SIEM
  • 4+ years of demonstrated expertise with Linux administration
  • Provide Tier 3 troubleshooting for Splunk and/or ArcSight issues, either within the tool or as part of an integrated team of professionals addressing larger issues
  • Configure the tools to work with Syslog, File and Database collection of events.
  • Create and edit content to both monitor and alert on security incidents.
  • Providing guidance to both internal and external Customer issues and supporting tickets
  • Act as the senior subject matter expert on the tool for interactions with other teams
  • Develop documentation to support the mission
  • Provide "on the job training" to teammates
  • Ability to create custom dashboards and reports;
  • Significant understanding of SQL, REGEX, Bash and Perl;
  • Deep knowledge optimizations for large networks;
  • Ability to create content for Splunk security alerting;
  • Demonstrated experience executing the responsibilities listed above
  • Proven experience leading a team and able to communicate with senior leadership and engineers
  • Provide on-call support when needed
  • An active TS/SCI w/ Polygraph is required for this position


Desired Qualifications
  • Ability to write Bash scripts
  • Knowledge of Windows systems administration


Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world's toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company's 32,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $10.19 billion for the fiscal year ended December 28, 2018. For more information, visit www.Leidos.com .

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here .

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com .

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Talent Community

Join our Talent Community to create a profile, enabling a streamlined application process and to help our recruiters better understand your areas of expertise and interest.

Join our Talent Community