Jobs and Careers
CA

Splunk / Python Integration Engineer

CACI International Inc
999 REMOTE, United StatesRemotefull_timeVerifiedPosted 25 Jul 2024
💰 $188,000/yr($89,500/yr$188,000/yr)

About the role

Splunk / Python Integration Engineer

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: None

Employee Type: Regular

Percentage of Travel Required: None

Type of Travel: None

* * *

What You’ll Get to Do

CACI is seeking a Splunk/Python Integration Engineer to support cybersecurity data collection, analysis, and mitigation.  The work will include support for cybersecurity-related projects that encompass automated event identification and incident response, cybersecurity implementation into a Splunk data-lake, analysis of data derived from cybersecurity tools and use the results of that analysis towards developing enhanced and automated queries, and preparation of presentation materials for Government managers.  The engineer will also work with the Integration Layer Architecture to develop an approach for expanding the scope of the existing data integration layer to accommodate data from an expanded set of data sources and data fields, as a part of a future solution deployment.

This position will support the Continuous Diagnostics and Mitigation (CDM) Program’s mission to safeguard and secure cyberspace in an environment where the threat of cyber-attack is continuously growing and evolving and is responsible for enhancing the security, resilience, and reliability of the Nation’s cyber and communications infrastructure.  The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks. This is a remote position where the candidate can work from any location within the United States, provided they are able to work on an eastern time zone schedule.

More About the Role

  • Engineer, implement and monitor Splunk security measures for the protection of computer systems, networks, and information
  • Identify and define system data collection requirements
  • Design computer security architecture and develop detailed cyber security designs using Splunk or other similar tools with breakthrough technology solutions
  • Create Python scripts to query data sets and integrate the data into dashboard solutions
  • Deploy Splunk into virtual and cloud environments (AWS and Azure)Prepare and document standard operating procedures and protocols for all designed and developed solutions that ensures detailed project documentation
  • Develop technical solutions and investigate new security tools to help mitigate security vulnerabilities and automate repeatable reports using Splunk data-lake or other similar tools
  • Develop query mechanisms using Splunk within hours of receiving a data request

You’ll Bring These Qualifications

  • Must be a US citizen and pass a background investigation.
  • Able to obtain and maintain a Department of Homeland Security (DHS) Suitability/Entry on Duty (EOD)
  • Proven work experience as a Splunk system security architect with a Splunk Enterprise Certified Architect certification
  • Experience in building and maintaining data integration and processing systems that receive data feeds from multiple disparate data sources
  • Knowledge of network design and network devices: Cisco, F5, Juniper, and Palo Alto with knowledge of applicable API integration
  • Demonstrated experience with Python programming with REST API based application development experience.
  • Experience using CI-CD tools such as GitLab / Puppet / Ansible for deploying Splunk applications / configurations.
  • Detailed technical knowledge of database and operating system security using Splunk attributes
  • Hands on experience with Splunk collecting cybersecurity data metrics from firewalls, intrusion detection systems, anti-virus software, vulnerability scanners, authentication systems, log management, content filtering, etc.
  • Knowledge of the implementation of attribute-based access control (ABAC) and role-based access control (RBAC) triggers for Splunk
  • Applied hands-on knowledge of the use of Splunk with two or more of the following toolsets: Axonius, Forescout, McAfee ePO, RedHat Enterprise Linux (RHEL and RHEL KVM), ServiceNow, Tanium, VMWare, Windows Server, Tenable, CrowdStrike
  • Experience architecting and implementing Axonius, including ingests from a variety of data source

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CACI International Inc

View company profile →