Cybersecurity Engineer – SIEM / Splunk

Electrosoft

Richmond (VA)

On-site

USD 150,000 - 160,000

Full time

2 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Electrosoft Services, LLC seeks a Cybersecurity Engineer specialized in SIEM/ELM to support a large-scale DoD cybersecurity environment. You will provide architecture, engineering, administration, content development, troubleshooting, and sustainment support for Splunk Core and Splunk Enterprise Security.

The role involves developing SIEM use cases, dashboards, and reports, integrating data feeds, and ensuring high availability through upgrades and tuning within a DoD setting.

Qualifications

  • 7+ years of relevant IT experience.
  • DOD Secret Clearance and eligibility for IT I.
  • IAT III and CND-IS certifications per DoD 8570/8140.
  • Experience configuring and maintaining Splunk ES/ Core and custom dashboards.

Responsibilities

  • Research, plan, install, configure, troubleshoot, and back up Splunk ELM/SIEM components.
  • Develop SIEM use cases, dashboards, reports, and data monitors.
  • Integrate data feeds and improve SIEM architecture for DoD environment.
  • Perform upgrades, maintenance, and capacity analysis of SIEM infrastructure.
  • Provide training and knowledge transfer to gov't and contractor personnel.

Skills

IT experience
Security clearance
DOD 8570/8140 IAT III
DOD 8570/8140 CND-IS
Linux+
Splunk proficiency
Splunk ES knowledge
Splunk Core knowledge

Tools

Splunk
Splunk Core
Splunk Enterprise Security
Linux+
Splunk Administrator

Job description

Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer.

Cybersecurity Engineer – SIEM / Splunk
Position Summary

Electrosoft is seeking a Cybersecurity Engineer specializing in Security Information and Event Management (SIEM) and Enterprise Log Management (ELM) to support a large-scale DoD cybersecurity environment. The engineer will provide architecture, engineering, administration, content development, troubleshooting, integration, and sustainment support for Splunk Core and Splunk Enterprise Security (ES).

Key Responsibilities
  • Research, plan, install, configure, troubleshoot, maintain, and back up components of the enterprise Splunk ELM/SIEM environment.
  • Enhance ELM and SIEM architecture by incorporating new data feeds, products, and security capabilities.
  • Integrate security event and data feeds into the Splunk environment.
  • Develop and implement SIEM use cases to improve cybersecurity situational awareness.
  • Develop customized dashboards, reports, data monitors, active channels, trends, correlation rules, and other SIEM content.
  • Analyze threat information from logs, IDS, intelligence reporting, vendor sources, and other cybersecurity sources.
  • Identify and elevate high-threat events to incident responders.
  • Perform event analysis and tuning to improve detection capabilities and reduce false positives.
  • Support the development and optimization of security rules and correlation capabilities.
  • Perform upgrades, maintenance, troubleshooting, and performance tuning of SIEM infrastructure.
  • Conduct network and capacity analysis to ensure the environment can support anticipated event volumes.
  • Analyze endpoint availability and data-collection capabilities.
  • Define and maintain appropriate user roles and access.
  • Evaluate data-storage requirements and their impact on SIEM architecture.
  • Support Security Test and Evaluation and Information Assurance assessments.
  • Review DoD policies and assess their impact on SIEM and cybersecurity architecture.
  • Develop and maintain technical standards, security architecture documentation, SOPs, and implementation documentation.
  • Conduct research and market analysis of emerging cybersecurity and SIEM technologies.
  • Provide technical training, briefings, and knowledge transfer to Government and contractor personnel.
Basic Qualifications
  • Seven (7) years of relevant IT experience
  • DOD Secret Clearance
  • Must be eligible for IT I
  • Relevant certification meeting DOD 8570/8140 IAT level III
  • Relevant certification meeting DOD 8570/8140 CND-IS
  • Computing Environment: Linux+, Splunk Administrator
  • Experience creating custom dashboards and reports in Splunk using threat data
  • Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).
Pay Range

$150,000 USD - $160,000 USD

Electrosoft is an Equal Opportunity Employer/Veterans/Disabled

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM/Splunk Engineer for DoD Cybersecurity
SIEM/Splunk Engineer for DoD Cybersecurity

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Senior SIEM & Splunk Engineer for DoD Cyber Defense
Senior SIEM & Splunk Engineer for DoD Cyber Defense

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Sr. Splunk / SIEM Engineer (TS Required)
Sr. Splunk / SIEM Engineer (TS Required)

augustschell • Alexandria (VA)

Hybrid
USD 100,000 - 130,000
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • Chesapeake (VA)

On-site
USD 110,000 - 160,000
Free Platinum-Level Medical/Dental/Vis
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+4
Splunk Engineer - Active TS/SCI Required
Splunk Engineer - Active TS/SCI Required

ENS Solutions, LLC • College Park (MD)

On-site
USD 80,000 - 110,000
Free Platinum-Level Medical/Dental/Vision coverage
401k Contribution from Day 1
PTO + 11 Paid Federal Holidays
+2
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000
Cyber Security Engineer
Cyber Security Engineer

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000