Enable job alerts via email!

SOC Analyst / Splunk Administrator

Apex Systems

Washington (District of Columbia)

Hybrid

USD 80,000 - 110,000

Full time

5 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled SOC Analyst / Splunk Administrator to join their dynamic team. This hybrid role combines SOC analysis with Splunk engineering, where you will leverage your expertise in administering Splunk, managing security events, and conducting thorough investigations. You will be responsible for creating custom content, optimizing dashboards, and collaborating with a team dedicated to cybersecurity excellence. This position offers the chance to work in a supportive environment that values innovation and professional growth, making it an exciting opportunity for those passionate about security and technology.

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401K with Company Match
Employee Stock Purchase Program
Professional Development Resources
Employee Assistance Program

Qualifications

  • 2-5 years of experience in network defense environments.
  • Strong analytical skills in computer network defense and incident handling.

Responsibilities

  • Administer Splunk and create custom SPL content.
  • Conduct security investigations and manage data in a SIEM.

Skills

Splunk Administration
Security Event Analysis
Incident Handling
Malware Analysis
Data Source Management
Analytical Skills
Communication Skills

Education

Splunk Admin Certification
Relevant Certifications (Security+, CySA+, GCIA, GCIH)

Tools

Splunk Enterprise Security
FireEye
Palo Alto
MS O365

Job description

Job Title: SOC Analyst / Splunk Administrator

Apex Systems is seeking a SOC Analyst / Splunk Administrator to work partially remote, with onsite presence in Washington, D.C. for 1 day per week.

Summary:

This hybrid role bridges SOC Analysis with Splunk Engineering and Content Creation. The candidate should be skilled in administering Splunk, creating custom SPL content, managing data in a SIEM, and conducting security investigations using Splunk ES.

The mid-tier candidate will have a solid understanding of cyber threats, TTPs, Threat Actors, Campaigns, and Observables, and be proficient in creating dashboards and notables in Splunk.

Familiarity with SOC tools such as intrusion detection systems, SIEM platforms, endpoint threat detection, and security operations ticketing is also desirable.

Requirements:
  • Must be a U.S. Citizen eligible for a Public Trust clearance.
  • 2-5 years of experience in network defense environments.
  • Splunk Admin Certification is required; equivalent experience of 15+ years may substitute.
  • Strong analytical skills in computer network defense, incident handling, hunting, and malware analysis.
  • Experience analyzing security events to identify true positives, conducting incident investigations, and implementing countermeasures.
  • Hands-on experience with managing and optimizing Splunk Enterprise Security.
  • Experience with data source management, troubleshooting, and onboarding.
  • Proficiency in dashboard and notable creation, visualizations, and report generation.
  • Ability to develop rules, filters, views, signatures, and scripts for analysis and detection.
  • Strong logical thinking, especially analyzing host and network security events.
  • Excellent organizational skills and attention to detail.
  • Knowledge of operating systems (Windows, macOS, Linux), Active Directory, networking protocols, and internet standards.
  • Experience with implementing security countermeasures in enterprise networks.
  • Strong communication skills.
Desired Qualifications:
  • Researching emerging threats and recommending monitoring strategies.
  • Experience with tools like FireEye, Palo Alto, and MS O365.
  • Relevant certifications such as Security+, CySA+, GCIA, GCIH.
  • Scripting or automation experience.
  • Knowledge of cloud security monitoring (AWS, Azure).
Education:

EEO Employer

Apex Systems is an equal opportunity employer committed to diversity and inclusion. We consider qualified applicants with criminal histories in accordance with applicable laws. For accommodations during the application process, contact employeeservices@apexsystems.com or call 844-463-6178.

About Apex Systems:

Apex is a leading IT services company serving clients worldwide. We value innovation, collaboration, and continuous learning, offering extensive resources, training, certifications, and benefits. Recognized for excellence, we have received awards such as ClearlyRated's Best of Staffing and Great Place to Work awards.

Benefits Overview:

Our benefits include medical, dental, vision, life, disability insurance, an Employee Stock Purchase Program, 401K with company match, HSA, Employee Assistance Program, discounts, professional development resources, and more. We support your growth with training, certifications, and leadership courses, along with dedicated support teams and career coaching.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Splunk Administrator - 100% Remote

Creative Solutions Services, LLC

Herndon

Remote

USD 80,000 - 110,000

2 days ago
Be an early applicant

SOC Analyst / Splunk Administrator

Apex Systems

Washington

Hybrid

USD 70,000 - 110,000

Yesterday
Be an early applicant

Mid - SOC Analyst / Splunk Administrator

Leidos

Washington

Hybrid

USD 104,000 - 190,000

6 days ago
Be an early applicant

AWS Cloud Engineer - Splunk

Peraton

Herndon

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

AWS Cloud Engineer - Splunk

Peraton

Remote

USD 70,000 - 110,000

2 days ago
Be an early applicant

AWS Cloud Engineer - Splunk

Peraton

Remote

USD 80,000 - 128,000

6 days ago
Be an early applicant

Splunk Architect - Remote

The Dignify Solutions, LLC

New York

Remote

USD 80,000 - 110,000

10 days ago

Security Content Engineer – Splunk

BlueVoyant

College Park

Remote

USD 80,000 - 120,000

30+ days ago

Sr. Site Reliability Engineer: Splunk Cloud Services

Splunk

North Carolina

Remote

USD 90,000 - 150,000

30+ days ago