Jobs and Careers
NA

Cyber Security Engineer III-IV (Splunk Content Developer/ES Search head Admin)

Navy Federal Credit Union
United Statesfull_timeVerifiedPosted 9 Apr 2024

About the role

We are looking for a Splunk Content Developer/ES Search head Admin that can come in to take ownership of day-to-day Operations with minimal spin-up time.  Successful candidate will be a member of a high performing team of certified Splunk Enterprise and Splunk ES administrators. You will partner with additional teams within Navy Federal Credit Union to protect the Navy Federal brand, data, and IT assets from cyber-based threats in support our Cybersecurity Operations Center (CSOC) and its associated programs. You will serve as technical interface to customers (analysts) for Splunk and Splunk ES, articulating technology and product positioning to both business and technical users. Successful candidates will work independently; must be self-starting self-motivated individual, be accountable and timely in their production and status reporting and communicate effectively both in writing and when speaking to groups. You will be expected to work to build and maintain relationships within and outside of the CSOC, all team members share this duty. This position will require a high level of attention to detail to the work performed, following process, and detailed updates/documentation using Jira.

•   Developing notable events, visualizations, forms, reports, alerts, dashboards, and visualizations to identify adversarial activity
•   Build and implement event correlation rules, logic, and content in the SIEM
•   Configure notable event actions, action menus and Adaptive Responses
•   Tune SIEM event correlation rules and logic to filter out security events associated with known and well-established network behavior, known false positives and/or known errors
•   Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate
•   Translate feedback from the business to Splunk technical requirement and solutions
•   Normalize data to ensure CIM compliance, and align with data models to accelerate queries, dashboards, and correlation searches
•   Maintain Splunk Apps, Technology Add-ons as required by Splunk ES upgrades
•   Research and look for opportunities to adopt the best practices and industry standards to enhance the SIEM, Fraud, and SOAR platforms
•   Monitor system stability and performance and ensure system availability, reliability, and usability
•   Troubleshoot and resolve Splunk-related technical issues, partnering with IT and SOC teams as needed
•   Always provide professional and courteous service with excellent verbal and written communications skills.
•   Participate in on-call rotation and respond to incident alerts
•   Stay abreast of the latest Splunk features, technologies, and industry trends, and make recommendations for continuous improvement
•   Follow Change & Configuration Management procedures in relevant tools (e.g. Jira, SNOW, etc.)
•   Ensure the completion of tasks and update tickets accordingly
 

•   Bachelor’s degree in computer science, Information Systems, Cybersecurity or comparable field of study, and/or equivalent work experience
•   Six (6) to eight (8) years of experience with Splunk in distributed deployments and at least two (2) years of experience in Splunk Cloud environments 
•   At least three (3) years of experience with Splunk Enterprise Security
•   Current Splunk Enterprise Certified Admin certification
•   Current Splunk Enterprise Security Certified Admin certification
•   Proficient at data administrative activities including parsing and normalizing events to the Splunk Common Information Model (CIM)
•   Proficiency aligning data to Splunk-developed add-ons for Windows, Linux, and common third-party devices and applications
•   Superb communication skills (both oral/written) including the ability to clearly communicate technical topics and risk to an audience than can include both engineers and executives
•   Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure
•   Experience with SIEM and/or SOAR platforms, including the development of automations and integrations
•   Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision
•   Knowledge of JIRA and Confluence
•   Knowledge of Change Management processes
•   Hands on experience in an agile environment

Desired Qualifications and Education Requirements

•   Current Splunk Enterprise Certified Architect
•   Current Splunk Core Certified Consultant
•   Expert-level knowledge and ability with Splunk Enterprise Security or integration with other Security Information and Event Management (SIEM) platforms
•   Knowledge of scripting languages like Python
•   Experience in the banking or finance industries a plus
•   Knowledge of version control practices and exp

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Navy Federal Credit Union

View company profile →