ISSO with current Clearance Secret or above ONLY

Idaho Falls, ID, US • Posted 4 days ago • Updated 4 days ago
Contract W2
18 Months
No Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Splunk
  • SPL
  • AITK
  • MITRE ATT&CK

Summary

Must have current, not active, DOE L, Q or TS and above to be qualified

Salary and if needed, per diem to be onsite in Idaho Falls Idaho. NO REMOTE WORK

1. Qualifying individual must be willing to relocate to Idaho Falls, Idaho.

2. Qualifying individual must have a current “L” or “Q” clearance OR Top Secret

3. Qualifying individual “MUST” have the following skillsets:

  • Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization
  • Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework
  • Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment
  • Strong understanding of the MITRE ATT&CK framework and detection engineering methodology
  • Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.)

4. Qualifying individual “NICE” to have the following skillsets:

  • Experience with detection-as-code practices and tools (Git, CI/CD pipelines)
  • Proficiency in Python for data processing and model development
  • Knowledge of SOAR platforms and detection automation
  • Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.)
  • Prior experience in a SOC, threat hunting, or incident response role

 

In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning. We’re looking for a candidate that lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts, we want to hear from you.

What the candidate is expected to perform:

  • Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES)
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to develop machine learning models for anomaly detection and advanced threat identification
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content
  • Create documentation, runbooks, and detection specifications to support downstream analysts
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10118931
  • Position Id: 9061676
  • Posted 4 days ago

Company Info

About United Global Technologies

Founded in 2009 by Elizabeth Bernstein and Jason Monastra, United Global Technologies is a SBA certified Women Owned Small Business (WOSB) IT and Engineering Services provider offering public and private sector clients over 32 years of information technology, engineering, and operational project services experience.

UGT was formed on the backbone of servicing mission-critical federal facilities with unclassified and classified personnel at the most vital locations across the country including Savannah River National Lab (SRNL), Savannah River Site (SRS), Nevada Test (NSTec), Oak Ridge Associated Universities (ORAU), Oak Ridge National Lab (ORNL), Los Alamos National Lab (LANL), Idaho National Lab (INL), FERMI, Brookhaven National Lab (BNL), West Valley and others. The company continues to expand our footprint offering commercial services to the largest companies in the world inclusive of Jacobs, CH2MH, Fluor, General Dynamics, Bechtel and other industry leaders across a diverse range of industrial verticals.

No other U.S.-based IT and engineering services company has the track-record and scope required to meet aggressive goals for all clients while offering the diversity business benefits of working with a certified EDWOSB/WOSB/SBE/DBE/MBE and HUB (NC) professional services firm. UGT, in addition, was selected with the past performance of the Department of Energy (DOE) into the Mentor Prot g program to support Stanford National Accelerator Laboratory (SLAC) in California.


Careers

Contact the job poster
Britt Bodie

Britt Bodie

Sr. IT recruiter @ United Global Technologies
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs