We are seeking for a Splunk Administrator to install and maintain Splunk infrastructure, gather requirements from customers, onboard data, and assist end users with search, dashboards, reports, and knowledge objects in support of the Compartmented Enterprise Services Office (CESO) NOC.
The customer is looking to transform the existing Secure Web Services (SWS) environment, which provides secure information sharing to the community, into a more mature service offering to meet the customer and intelligence communities. As part of this task order, the customer will manage the commercial cloud migration and disestablishment of legacy systems, fully automate the continuous development & continuous integration environment, fourth estate consolidation, professionalize services – ITIL/DevSecOps based processes, improve the customer experience 1st call resolution, and achieve development of a service catalog for Defense Working Capital Fund (DWCF) Model.
This position is in either Alexandria, VA, or Arlington, VA with occasional/situational travel.
- Administer Splunk in Windows and Linux environments
- Work with existing and custom Splunk applications and add-ons to fulfill customer needs
- Provide operations and maintenance support for a distributed Splunk environment consisting of heavy forwarders, indexers, and search head servers, spanning security, performance, and operational roles
- Editing and maintaining Splunk configuration files and apps
- Onboard data to Splunk via forwarder, scripted inputs, TCP/UDP, and modular inputs from a variety of sources.
- Provider operational support for Splunk Universal Forwarder on Linux and Windows endpoints
- Manage, and support automation solutions for Splunk deployment and orchestration in on-premise and cloud environments
- Bachelor’s degree in Computer Science or IT and 4+ years of experience; Additional experience may substitute for degree
- Current Splunk Enterprise Certified Admin certification
- IAT Level II Baseline Certification (e.g. CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP)
- Prior experience with the customer and the customer's support to mission partners
- TS/SCI w/CI Poly Preferred
- TS/SCI minimum with the ability to obtain CI Polygraph