Summary
Join GuidePoint Security as a Splunk Security Engineer and drive complex security deployments, collaborating with clients to solve unique problems. You will support security deployments, leveraging Splunk's potential to achieve cybersecurity strategies. Collaborate across the organization, share best practices, and create innovative solutions to maximize Splunk's value. Enable customers to independently solve future challenges. This role requires a deep understanding of cyber threats and 5+ years of Splunk experience, along with specific certifications and technical skills.
Requirements
- Must have an understanding of cyber-based threat techniques and procedures to compare industry related events, exposures, and incidents with open source and gathered intelligence research to determine threat capability and intent, and the potential impact of the threat on customer network architecture and operations
- 5+ years of Splunk architecture, implementation, and troubleshooting experience
- REQUIRED: Splunk Enterprise Certified Architect or Splunk Core Certified Consultant
- Splunk Enterprise Security experience
- Proficiency developing log ingestion and aggregation strategies
- Expertise developing security-focused content for Splunk, including creation of complex threat detection logic and operational dashboards
- Familiarity with key security events on common IT platforms
- Deep proficiency in client and server operating systems especially Linux but also Windows
- General networking and security troubleshooting (firewalls, routing, NAT, etc.)
- Scripting and development skills (BASH, Perl, Python or Java) with strong knowledge of regular expressions
- Ability to autonomously prioritize and successfully deliver across a portfolio of projects
Responsibilities
- Drive complex security focused deployments of Splunk while working side by side with the customers to solve their unique problems across a variety of use cases
- Work with our customers to understand their security posture and requirements
- Support our security deployments by unlocking the potential of Splunk to assist our customers in achieving their Cyber Security strategy
- Collaborate across the entire organization to bring access to product and technical teams to get the right solution delivered and drive innovation gathered from customer input
- Leverage previous experiences, share best practices and create innovative solutions to push user adoption and maximize the value of Splunk
- Enable customers to solve the next wave of questions on their own
Preferred Qualifications
- Familiar with Configuration and Administration with Enterprise SIEM and experience in the Integration of multiple SIEM tools into a Single Architecture
- Working Knowledge of Operating System Auditing (both Syslog and Window Event Log) preferred
- Experience authoring security runbooks, policy, and best practice documentation, and implementing SOAR platforms such as Phantom (Splunk SOAR), or Demisto (XSOAR)
- Bachelorβs degree in a relevant discipline or equivalent professional experience
Benefits
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family) and GPS will contribute in one lump sum: ($500 per EE annually / $1000 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.