Splunk Security Engineer

Booz Allen Hamilton Inc.
Mclean, VA
Apr 17, 2018
Apr 18, 2018
Engineering, Security
Full Time
Job Description Job Number: R0023803 Booz Allen Hamilton has been at the forefront of strategy and technology for more than 100 years. Today, the firm provides management and technology consulting and engineering services to leading Fortune 500 corporations, governments, and not-for-profits across the globe. Booz Allen partners with public and private sector clients to solve their most difficult challenges through a combination of consulting, analytics, mission operations, technology, systems delivery, cybersecurity, engineering and innovation expertise. Splunk Security Engineer Key Role: Develop security focus content for complex client Splunk deployments, focus on the creation of complex threat detection logic, dynamic operational dashboards, and data source onboarding and configure and deploy enterprise security, operate Splunk using Security Information and Event Management (SIEM) or Security Event Management (SEM), and architect log management or ingestion solutions. Develop automation for security tools management and create customized searches and applications use programming and development expertise, including CSS, HTML, or JavaScript, Python, Shell Scripting, and regular expression. Act as a Splunk Search Language (SPL) expert, develop network or entity based anomaly detection alert logic in SPL using the ML toolkit. Basic Qualifications: * 3+ years of experience with IT * 1+ years of experience with Splunk, network security, system security, and supporting Security Information and Event Management (SIEM) * 1+ years of experience with rule and advanced logic creation in Splunk * Experience with using scripting languages to automate tasks and manipulate data * Experience with working in a large enterprise environment * Knowledge of enterprise logging, including application, OS, and security technology logging * Knowledge of regular expressions * Ability to demonstrate SPL expertise * Ability to travel up to 80% of the time * BA or BS degree Additional Qualifications: * 1+ years of experience with performing hunt activities in an incident response role * Experience with enterprise-scale operations and maintenance environments * Experience with programming a plus * Experience with Python * Experience with security tools, including Firewall, IDS, Active Directory, Nmap, Burp, Proxy, or Bro * Knowledge of networking protocols * BA or BS degree in CS, IT, or related field * Splunk Admin or Architect certification Integrating a full range of consulting capabilities, Booz Allen is the one firm that helps clients solve their toughest problems by their side to help them achieve their missions. Booz Allen is committed to delivering results that endure. We are proud of our diverse environment, EOE, M/F/Disability/Vet. AFH26, CMCL, TMJ16 SDL2017

Similar jobs