Splunk SIEM Specialist, Senior, TS/SCI, Tampa, FL

  • General Dynamics Information Technology
  • Tampa, FL

Full Time

    Job Description

    Please take this opportunity to join one of GDIT's fastest long-standing growing programs! US Battlefield Information Collection and Exploitation System eXtended (US BICES-X) is a cutting edge program supporting DoD intelligence information sharing on current and emerging global threats to mission and coalition partners and emerging nations. With an internationally dispersed team supporting each combatant command, the US BICES-X Team is in direct support of the war fighter and their missions. We are seeking a creative and driven professional with a passion for solving real-world issues on a cross-functional, fast-paced team. You will be part of a dynamic team that is delivering a business driven Enterprise Network to support BICES Global Enterprise Mission Support Services increasing performance, security, scalability, and stability while reducing costs and complexity resulting in increased supportability.

    • Performs Cybersecurity Infrastructure Support activities (formally known as Cyber Network Defense) for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
    • Ensure the continuity and smooth functionality of the Splunk service, its associated components, and its integrations with other services.
    • Design and implement solutions to address business problems, understanding the Splunk architecture requirements for scalability, security, performance, and cost-efficiency.
    • Ensure the security of the Splunk environment by performing proactive health checks and keeping abreast of new threats and vulnerabilities that may affect them.
    • Remain current and up to date with emerging technologies, organization requirements and enhancements & develop proposals for changes that may be required.
    • Develop best practices, standards, and architectural principles for the Splunk service.
    • Assist/engage other system owners and project managers that have integration requirements with the various other enterprise systems.
    • Assist/engage other engineering teams for problem determination of incidents.
    • This position will be working within our Cybersecurity Infrastructure environment providing but not limited to; Implementation and Administration of Security Ops, SPLUNK, ACAS, HBSS, and security related activities to secure and harden systems.
    • Utilize available resources to conduct Cybersecurity activities, and report to senior GDIT and government personnel on overall program security posture.
    • Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), ACAS vulnerability scanner, and DISA SCAP to mitigate those findings for Solaris, Linux, Windows, and associated network operating systems.
    • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
    • Provides guidance and work leadership to less-experienced technical staff members.
    • Maintains current knowledge of relevant technology as assigned.
    • Participates in special projects as required.

    Required Qualifications:
    • 5+ years of experience required.
    • Must possess and maintain a DoD TS/SCI clearance.
    • BA/BS degree and Master's Degree required - may substitute additional years of experience.
    • Red Hat Enterprise Linux operation and maintenance experience.
    • SPLUNK & SYSLOG operating and management experience is a must.
    • Comprehensive knowledge of data security administration principles, methods, and techniques
    • Must meet DOD 8570.01M requirements for IAT Level II & CSSP-Infrastructure Support.
    • Requires understanding of DHS/DoD policies and procedures, including FIPS 199, FIPS 200, NIST 800-53, DHS 4300A SSH and other applicable policies.

    Preferred Qualifications:
    • The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast-paced team-oriented environment.
    • Extensive experience knowledge of Splunk architecture, distributed components (indexer clusters, forwarders, search head clusters, deployment servers, dashboards etc).
    • Strong knowledge of Splunk Enterprise Security at administration and use case level.
    • Deep understanding of:
      • Splunk language (SPL)
      • Intermediate Python or PowerShell scripting a must
      • CSS, XML, macros, and JavaScript.
      • External systems management products & feeds, particularly, but not limited to the M365 security portfolio.
      • Optimised data architectures & data analytics.
      • WANs and LANs and TCP/IP.
    • Must have a thorough (advanced to expert) understanding of IT security and implementation of security related guidelines and impact on IT infrastructures.
    • Problem solving abilities across enterprise multiple technology environments with complex integrations.
    • Strong time management skills.
    • Strong verbal and written communication skills; must be able to communicate effectively with a wide variety of audiences, both business and technical.
    • Work collaboratively and cooperatively with diverse geographical and cultural groups.
    • The work is typically performed in an office environment, which requires normal safety precautions; work may require some physical effort in the handling of light materials, boxes or equipment.

    #dpost #cjobs #cjpost #isdcj #GDITRecruiter #BICES #excitingMPEteam

    Work Requirements

    Years of Experience
    5 + years of related experience

    * may vary based on technical training, certification(s), or degree

    Travel Required

    U.S. Citizenship Required

    About Our Work

    We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.
    COVID-19 Vaccination
    GDIT does not have a vaccination mandate applicable to all employees. To protect the health and safety of its employees and to comply with customer requirements, however, GDIT may require employees in certain positions to be fully vaccinated against COVID-19. Vaccination requirements will depend on customer site requirements.

    GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.