Castalia Systems ยท 4 months ago
Security Information Event Manager (SIEM) Administrator
Castalia Systems is a proven business partner providing mission critical solutions to the Federal Government. The Security Information Event Manager (SIEM) Administrator is responsible for managing the organization's SIEM system using Splunk, implementing and optimizing it for effective security monitoring and incident response.
AnalyticsArtificial Intelligence (AI)RoboticsSoftware
Responsibilities
Implement, install, and troubleshoot Splunk Enterprise (SE) and Splunk Enterprise Security (ES) systems
Maintain and administer SE and ES configurations, indexes, apps, and knowledge objects
Monitor system health, capacity, and performance to proactively address issues
Configure new data inputs to expand data collection capabilities
Create security dashboards, reports, alerts, and notifications
Collaborate with system administrators to enhance security monitoring capabilities
Perform updates and patches on the Splunk platform
Audit and review security practices to prevent security incidents
Maintain documentation of system configurations and changes
Qualification
Required
High School Diploma
At least 4+ years of system, network administration, or developer experience and 2+ years of Splunk administration. A Bachelor's degree in Computer Science can be considered in lieu of the 4 years of system/network admin or developer experience
IAW DoD 8140.03-M, must meet the Intermediate Proficiency Level qualifications
IAM-II Certification (one or more of the following): CISM, CISSP (OR ASSOCIATE), GSLC, CCISO, CAP, CASP+ CE, HCISSP
Must have Splunk Enterprise Certified Admin credential
Must have experience administering Linux servers
Must have experience with SIEM Content Development
Demonstrated experience of strong analytical and problem-solving skills
Excellent communication and collaboration skills
Preferred
Red Hat Linux administrator certification
Experience with Splunk Enterprise Security
Experience in a virtualized environment
One or more relevant CND certifications: CISSP, CASP, OSCP, CySA+, CEH, or GCIH
Benefits
Medical, dental, and vision coverage
401k matching
Generous PTO
Paid holidays
Professional training opportunities
Pet insurance