General Dynamics Information Technology hiring for Splunk Administrator - Cyber Security Analyst Advisor jobs in Tampa, FL, US
Title: Splunk Administrator - Cyber Security Analyst Advisor
Clearance Needed: TS/SCILocation: USA FL MacDill AFB - 7701 Tampa Point Blvd (FLC097)Please take this opportunity to join one of GDIT's fastest long-standing growing programs! US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) is a cutting edge program supporting DoD intelligence information sharing on current and emerging global threats to mission and coalition partners and emerging nations. With an internationally dispersed team supporting each combatant command, the US BICES-X team is in direct support of the war fighter and their missions. We are seeking a creative and driven professional with a passion for solving real world issues on a cross-functional, fast paced team. As part of the Defensive Cyber Operations Team, you'll be charged with maintaining the Cyber Security Posture for Enterprise data centers, workstations, and remote locations across the globe.
- Performs Defensive Cyber Operations (DCO) activities (formally known as Cyber Network Defense) for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
- Ensure the continuity and smooth functionality of the Splunk service, its associated components, and its integrations with other services, Operations and Sustainment.
- Design and implement solutions to address business problems, understanding the Splunk architecture requirements for scalability, security, performance, and cost-efficiency.
- Ensure the security of the Splunk environment by performing proactive health checks and keeping abreast of new threats and vulnerabilities that may affect them.
- Remain current and up to date with emerging technologies, organization requirements and enhancements & develop proposals for changes that may be required.
- Develop best practices, standards, and architectural principles for the Splunk service.
- Assist/engage other system owners and project managers that have integration requirements with the Splunk.
- Assist/engage other engineering teams for problem determination of incidents.
- This position will be working within our DCO environment providing but not limited to; Implementation and Administration of Security Ops, SPLUNK, SYSLOG, ACAS, HBSS, and security related activities to secure and harden systems.
- Utilize available resources to conduct Cybersecurity activities, and report to senior GDIT and government personnel on overall program security posture.
- Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Solaris, Linux, Windows, and associated network operating systems.
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Provides guidance and work leadership to less-experienced technical staff members.
- Maintains current knowledge of relevant technology as assigned.
- Participates in special projects as required.
Required Qualifications:
- 8+ years of technical experience required.
- BA/BS required - may substitute additional years of experience
- Must possess and maintain a TS/SCI Clearance.
- SPLUNK Core Certified Power User
- Experience with infrastructure including but not limited to: data center operations, server hardware, operating systems (Windows, Linux), web servers, databases, virtualization (VMware), networking, storage, monitoring, etc.
- May be required to work evening, weekend, and holiday hours as required.
- Must meet DoD 8570 requirements and be eligible for IAT level II & CSSP-IS access upon hire for positions with elevated privileges and must obtain ITIL V4 Foundation within six months of hire.
- Depending on job assignment, additional specific certifications may be required.
Preferred Qualifications:
- The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
- Extensive experience and knowledge of Splunk architecture, distributed components (indexer clusters, forwarders, search head clusters, deployment servers, dashboards etc).
- Strong knowledge of Splunk Enterprise Security at administration and use case level.
- Deep understanding of:
- Splunk language (SPL)
- Intermediate Python or PowerShell scripting a must
- CSS, XML, macros, and JavaScript.
- External systems management products & feeds, particularly, but not limited to the M365 security portfolio.
- Optimised data architectures & data analytics.
- WANs and LANs and TCP/IP.
- Must have a thorough (advanced to expert) understanding of IT security and implementation of security related guidelines and impact on IT infrastructures.
- Problem solving abilities across enterprise multiple technology environments with complex integrations.
- Strong time management skills.
- Strong verbal and written communication skills; must be able to communicate effectively with a wide variety of audiences, both business and technical.
- Work collaboratively and cooperatively with diverse geographical and cultural groups.
- The work is typically performed in an office environment, which requires normal safety precautions; work may require some physical effort in the handling of light materials, boxes or equipment.
Work Requirements.cls-1{fill:none;stroke:#5b6670;stroke-miterlimit:10;stroke-width:2px} Years of Experience 8 + years of related experience* may vary based on technical training, certification(s),
or degree.cls-2{fill:none;stroke:#5b6670;stroke-miterlimit:10;stroke-width:2px} CertificationTravel Required None.cls-3{fill:none;stroke:#5d666f;stroke-miterlimit:10} Citizenship U.S. Citizenship RequiredAbout Our WorkWe are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.