Splunk/SIEM Administrator – Senior Cybersecurity Administrator
General Dynamics Information TechnologyAbout the role
Type of Requisition:
RegularClearance Level Must Currently Possess:
Top Secret/SCIClearance Level Must Be Able to Obtain:
Top Secret/SCIPublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
RedHat, SIEM Tools, Splunk Enterprise Security, Splunk Infrastructure MonitoringCertifications:
NoneExperience:
5 + years of related experienceUS Citizenship Required:
YesJob Description:
Please take this opportunity to join one of GDIT’s fastest long-standing growing programs! US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) is a cutting edge program supporting DoW intelligence information sharing on current and emerging global threats to mission and coalition partners and emerging nations. With an internationally dispersed team supporting each combatant command, the US BICES-X team is in direct support of the war fighter and their missions. We are seeking a creative and driven professional with a passion for solving real world issues on a cross-functional, fast paced team.
As part of the Defensive Cyber Operations Team, you’ll be charged with maintaining the Cyber Security Posture for Enterprise data centers, workstations, and remote locations across the globe.
Responsibilities:
- Performs Defensive Cyber Operations (DCO) activities (formally known as Cyber Network Defense) for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
- Ensures the continuity and smooth functionality of the Splunk/SIEM service, its associated components, and its integrations with other services.
- Ensure the security of the Splunk environment by performing proactive health checks and keeping abreast of new threats and vulnerabilities that may affect them.
- Assist/engage other system owners and project managers that have integration requirements with the various other enterprise systems.
- Assist/engage other engineering teams for problem determination of incidents.
- Develop best practices, standards, and architectural principles for the Splunk service.
- Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Linux, Windows, and associated network operating systems.
- Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance.
- Design and implement solutions to address business problems, understanding the Splunk architecture requirements for scalability, security, performance, and cost-efficiency.
- Maintains current knowledge of relevant technology as assigned
- Participates in special projects as required.
Required Qualifications:
- 5+ years of experience required.
- Must possess and maintain a Top Secret/SCI clearance.
- BA/BS degree required or equivalent work experience.
- Red Hat Enterprise Linux operation and maintenance experience.
- SPLUNK & SYSLOG operating and management experience is a must.
- Must meet DoW 8140.03 requirements and be eligible for IAT level II and CSSP Infrastructure Support access upon hire for positions with elevated privileges and maintain ITIL V3 Foundation certification.
- Requires familiarity with network concepts, user authentication, and digital signatures.
- Requires understanding of DOW RMF
Preferred Qualifications:
- The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
- Extensive experience knowledge of Splunk architecture, distributed components (indexer clusters, forwarders, search head clusters, deployment servers, dashboards etc).
- Strong knowledge of Splunk Enterprise Security at administration and use case level.
- Deep understanding of:
- Splunk language (SPL)
- Intermediate Python or PowerShell scripting a must
- CSS, XML, macros, and JavaScript.
- External systems management products & feeds, particularly, but not limite
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s