Splunk Detection Engineer
Job Locations: US-MD-Bethesda
ID: 2024-3410
Category: Information Technology
Type: Full Time
Overview
Edgewater Federal Solutions is currently seeking a Splunk Detection Engineer to provide support to an Edgewater Federal government contract.
Responsibilities
- Identify and respond to complex computer security incidents, communicate findings, and modify defenses and response measures as appropriate.
- Develop methods, techniques, and standards and communicate findings to multiple audiences.
- Work on complex cyber issues, providing guidance as appropriate to other cyber security personnel.
- Contribute to the integration of malware analysis, forensic investigation, and threat research into incident response and long-term understanding of threats.
Qualifications
- Bachelor's degree in a technical field and 10 years' experience. (Additional education and/or experience may reduce these requirements.)
- In lieu of a degree, relevant experience is applicable.
- U.S. Citizenship is required per contract to obtain and maintain a U.S. Security clearance.
- Strong Splunk Experience, including developing and maintaining quality queries, dashboards, custom views, saved searches, and alerts for internal technical operations team business application owners.
- Lead and/or support efforts to prepare for, monitor, detect, analyze/confirm, contain, remediate, and recover from security incidents.
- Conduct deep analysis and hunting operations.
- Provide Analyst training and workshops on using Splunk.
- Develop and implement automation and efficiencies with Splunk.
- A thorough understanding of the cyber security environment, including network and host system security issues and concepts, compliance, and certification.
- Thorough understanding of common network and host-based attacks, attack methods, network defense architectures, and security tools.
- Extensive experience with one or more of the following: malware analysis and reverse engineering; enterprise host and memory forensics; network forensics and packet analysis; incident response and incident coordination; penetration testing.
- Experience leading projects or mentoring junior analysts.
- Strong analytical, documentation, and communication skills and the ability to collaborate well in a dynamic team environment.
Desired Qualifications:
- Enterprise forensics tools.
- Memory analysis techniques.
- Dynamic analysis of software samples via debuggers such as OllyDbg or IDA debugger.
- Network signature creation.
- ArcSight, Splunk, or similar tools.
- Automated analysis and scripting with Python, Perl, or similar languages.
- Tool integration and event correlation with differing APIs.
About Us
Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Small Companies for 2018 through 2024.
It has been and continues to be the policy of Edgewater Federal Solutions to provide equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, veteran status, and/or other statuses protected by applicable law.
#J-18808-Ljbffr