REQ#: RQ184236 Public Trust: NACI (T1) Requisition Type: Regular Your Impact Own your opportunity to manage the network that makes mission success possible. Make an impact by using your skills to deliver One GDIT Network for our clients. Job Description Own your career as a Splunk Engineer at GDIT. Here, you'll have the opportunity to build strong lines of cyber defense using cutting-edge technologies. Your work in cyber security at GDIT will have an impact on securing our clients' missions and ensuring we anticipate the threats of tomorrow. At GDIT, people are our differentiator. As Splunk Engineer, you will help ensure today is safe and tomorrow is smarter. Our work depends on a Splunk Engineer joining our team to provide technical expertise in support of Cyber innovation. HOW A SPLUNK ENGINEER ADVISOR WILL MAKE AN IMPACT: * Support ongoing OMB M-21-31 efforts
* Maturing Splunk Data Lake under CIM Compliance Model
* Prioritizing data sources
* Identifying parsing and tagging issues
* Working with our Splunk Core administrator team to fix the parsing and tagging issues
* Updating CIM data models
* Working with our Threat Intelligence team to add signatures and detections in Splunk Enterprise Security's Threat Intelligence Framework
* Working with our Incident Response team
* Creating and tuning detections for attacks and vulnerabilities in Splunk Enterprise Security
* Fixing issues with the data in Splunk, such as missing fields or missing data types
* Assist our IR team with search queries
* Creating scripts to automate tasks
* Using Splunk SOAR to create and improve existing automation use cases/playbooks
* Configuring and maintaining the Splunk Enterprise Security Asset and Identity Framework
* Identifying sources for asset data
* Identifying sources for asset location and ownership information
* Optimizing and Tuning Splunk UBA
* Assisting Splunk users with creating queries, reports and dashboards WHAT YOU'LL NEED TO SUCCEED: * BA/BS and 8+ years of relevant experience or equivalent years of experience
* 2+ years of Splunk Administration experience
* Active Splunk Enterprise Security Admin and Splunk Advanced Power User certifications
* Security+/GSEC/CASP/CISSP/Cloud or equivalent 8570 Cyber Security Certification
* Ability to manage long term projects
* Proactively identify and correct problems
* Writing documentation and SOPs
* Working with vendor support to resolve issues
* Ability to work with other teams at the EPA, such as firewall, networking and vulnerability management teams
* Must possess or be able to obtain and maintain Public Trust
* US Citizenship required NICE TO HAVES: * Previous experience at the EPA
* Basic knowledge about incident response, threat intelligence and vulnerability management
* Familiar with SCCM
* Familiar with Microsoft Defender
* Familiar with asset management, Xacta, FISMA systems, ADC process
* Ability to write scrips in PowerShell and Paython
* Existing EPA privileged account GDIT IS YOUR PLACE: * Full-flex work week to own your priorities at work and at home
* 401K with company match
* Comprehensive health and wellness packages
* Internal mobility team dedicated to helping you own your career
* Professional growth opportunities including paid education and certifications
* Cutting-edge technology you can learn from
* Rest and recharge with paid vacation and holidays Work Requirements Years of Experience 8 + years of related experience * may vary based on technical training, certification(s), or degree Certification Travel Required Less than 10% Citizenship U.S. Citizenship Required Salary and Benefit Information The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. View information about benefits and our total rewards program. About Our Work We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.
* Maturing Splunk Data Lake under CIM Compliance Model
* Prioritizing data sources
* Identifying parsing and tagging issues
* Working with our Splunk Core administrator team to fix the parsing and tagging issues
* Updating CIM data models
* Working with our Threat Intelligence team to add signatures and detections in Splunk Enterprise Security's Threat Intelligence Framework
* Working with our Incident Response team
* Creating and tuning detections for attacks and vulnerabilities in Splunk Enterprise Security
* Fixing issues with the data in Splunk, such as missing fields or missing data types
* Assist our IR team with search queries
* Creating scripts to automate tasks
* Using Splunk SOAR to create and improve existing automation use cases/playbooks
* Configuring and maintaining the Splunk Enterprise Security Asset and Identity Framework
* Identifying sources for asset data
* Identifying sources for asset location and ownership information
* Optimizing and Tuning Splunk UBA
* Assisting Splunk users with creating queries, reports and dashboards WHAT YOU'LL NEED TO SUCCEED: * BA/BS and 8+ years of relevant experience or equivalent years of experience
* 2+ years of Splunk Administration experience
* Active Splunk Enterprise Security Admin and Splunk Advanced Power User certifications
* Security+/GSEC/CASP/CISSP/Cloud or equivalent 8570 Cyber Security Certification
* Ability to manage long term projects
* Proactively identify and correct problems
* Writing documentation and SOPs
* Working with vendor support to resolve issues
* Ability to work with other teams at the EPA, such as firewall, networking and vulnerability management teams
* Must possess or be able to obtain and maintain Public Trust
* US Citizenship required NICE TO HAVES: * Previous experience at the EPA
* Basic knowledge about incident response, threat intelligence and vulnerability management
* Familiar with SCCM
* Familiar with Microsoft Defender
* Familiar with asset management, Xacta, FISMA systems, ADC process
* Ability to write scrips in PowerShell and Paython
* Existing EPA privileged account GDIT IS YOUR PLACE: * Full-flex work week to own your priorities at work and at home
* 401K with company match
* Comprehensive health and wellness packages
* Internal mobility team dedicated to helping you own your career
* Professional growth opportunities including paid education and certifications
* Cutting-edge technology you can learn from
* Rest and recharge with paid vacation and holidays Work Requirements Years of Experience 8 + years of related experience * may vary based on technical training, certification(s), or degree Certification Travel Required Less than 10% Citizenship U.S. Citizenship Required Salary and Benefit Information The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. View information about benefits and our total rewards program. About Our Work We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.