Cyber Security Analyst

Makoa

Arlington, Northern (VA, KY)

Hybrid

USD 110,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Makoa in Arlington, VA is seeking a cybersecurity engineer to implement and manage Splunk infrastructure, monitor threats and ensure compliance in a federal context. The role includes patching servers, maintaining Linux environments, and enforcing security policies while coordinating with PMO and vendor teams.

The ideal candidate will have hands-on experience with Splunk/ELK, strong Linux skills, and active security certifications, enabling effective incident response and documentation across

Qualifications

  • Demonstrated experience working with complex system implementations and organizational processes to include maintaining system documentation.
  • Strong understanding, proficiency and experience with Linux and ability to effectively manage, secure and troubleshoot Linux-based environments.
  • CompTIA Linux+ or LPIC-1/LPIC-2 certification or Red Hat Certified System Administrator.
  • Familiarity with Splunk, Elastic Stack (ELK) or similar.
  • Active CompTIA Security+ certification.

Responsibilities

  • Facilitate and implement Splunk infrastructure to ingest, analyze and visualize machine generated data.
  • Create dashboards, alerts and reports for threat detection.
  • Patch and maintain servers to meet security compliance standards.
  • Ensure that the Linux servers are operational and reporting properly.
  • Administer and manage security posture via deployment of security policies and threat monitoring.
  • Troubleshoot application and server issues and respond to federal customer service requests.
  • Interface with PMO and vendor support groups to support Cyberspace Task Order efforts.
  • Create/Update documentation to support Splunk team requirements and maintenance.
  • Engage in weekly Splunk engineering meetings for agency mitigation and compliance.

Skills

Linux administration
Splunk
Security incident response
Documentation
Communication with customers

Education

BS/BA in Computer Science, MIS, or related IT discipline

Tools

Splunk
Elastic Stack (ELK)

Job description

Job Details

Job Location: Arlington, VA 22201


Position Type: Full Time



  • Facilitate and implement Splunk infrastructure to ingest, analyze and visualize machine generated data and deploy, configure and maintain Splunk Enterprise components such as indexers, Search Heads and Forwarders.

  • Create dashboards, alerts and reports for threat detection.

  • Patch and maintain servers continuously to meet security compliance standards.

  • Ensure that the Red Hat Enterprise Linux servers are operational and reporting properly.

  • Administer and manage the organization’s security posture via deployment of security policies (Microsoft Intune), threat monitoring & response (Microsoft Defender/Sentinel), data governance-Data Loss Prevention (Microsoft Purview), configuring log analytics-develop detection rules & playbooks (Microsoft Sentinel) and ensure compliance.

  • Troubleshooting application and server issues and responding to federal customer service requests.

  • Utilizes software and hardware tools and identifies and diagnoses complex problems and factors affecting performance.

  • Support incident response efforts by identifying vulnerabilities related to emerging threats and zero-day exploits.

  • Interfaces with PMO and vendor support service groups to support Cyberspace Task Order efforts and ensure proper escalation during outages or periods of degraded system performance.

  • Create/Update documentation needed to support the Splunk team requirements, taskings, deliverables, and maintenance of the tool.

  • Engage in weekly Splunk engineering meetings in support of the agency’s mitigation, compliance, assessment efforts and initiatives.

  • Monitor and track vulnerabilities, End-of-Life and priority action items.

  • Design, build, and implement network systems.

  • Perform cyber investigations and analysis.

  • Research and analyze a variety of commodity and APT based malware and techniques.

  • Search our existing infrastructure for signs of malware and malicious events not detected by our existing security controls.

  • Administer Assured Compliance Assessment Solution (ACAS) system comprised of Security Center, Nessus Scanner and the Nessus Network Monitor.

  • Administer Trellix ESS, including ePolicy Orchestrator (ePO), Solidcore, and DLP.

  • The ability to work independently as well as collectively within a team, apply critical thinking techniques, and effectively communicate with federal customers and other team members, both orally and in writing.


Qualifications


  • Demonstrated experience working with complex system implementations and organizational processes to include maintaining system documentation.

  • Strong understanding, proficiency and experience with Linux and ability to effectively manage, secure and troubleshoot Linux-based environments.

  • CompTIA Linux+ or Linux Professional Institute (LPIC-1/LPIC-2) certification or Red Hat Certified System Administrator

  • Familiarity with Splunk, Elastic Stack (ELK) or similar.

  • Active CompTIA Security+ certification


Preferred but not required


  • Splunk Enterprise Certified Administrator or Splunk Enterprise Certified Architect

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)

  • Microsoft Certified: Cybersecurity Architect (SC-100)

  • Microsoft Certified: Azure Fundamentals (AZ-900)

  • CompTIA CySA+


Minimum Education Required


  • BS/BA degree in Computer Science, Management Information Systems, or related IT discipline.

  • ALLOWABLE SUBSTITUTION: An additional four (4) years of experience can be substituted for a BS or BA degree.

  • Ability to pass a high-level background investigation

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Splunk Cyber Security SME
Splunk Cyber Security SME

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 160,000
CYBERSECURITY ENGINEER 4 – SIEM / SPLUNK ENGINEER
CYBERSECURITY ENGINEER 4 – SIEM / SPLUNK ENGINEER

iP-Plus Consulting, Inc. • Richmond (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates Inc. • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates, Inc • Richmond (VA)

On-site
USD 110,000 - 150,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate, LLC. • Richmond (VA)

On-site
USD 110,000 - 140,000
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Cybersecurity Engineer
Cybersecurity Engineer

ZealHire Inc. • Richmond (VA), Northern (KY)

Hybrid
USD 110,000 - 190,000
Splunk Engineer
Splunk Engineer

Ashburn Consulting • Camp Springs (MD)

On-site
USD 170,000 - 195,000
Senior Splunk Cyber Security Engineer
Senior Splunk Cyber Security Engineer

MANTECH • Chantilly (VA)

On-site
USD 120,000 - 180,000