Apavo Corporation · 1 month ago
Splunk Administrator
Apavo Corporation is a leader in cybersecurity services for military, defense, and critical infrastructure industries. The Splunk Administrator will support the organization's Splunk infrastructure, ensuring stability, performance, and security compliance while collaborating with the Department of Defense.
Computer & Network Security
Responsibilities
Provide expertise as it relates to Splunk implementations. Recommend and support changes to Splunk deployments
Support Indexer Clustering, Search Head Clustering, and Forwarders
Monitor, troubleshoot, and analyze overall health of Splunk infrastructure to include daily indexing volume, search volume and performance, data source reporting, user activity reporting, and custom apps/dashboards/visualizations
Perform root cause analysis on any issues with recommendations. Implement tactical and strategic solutions to problems
Develop, manage, and maintain documents supporting Splunk architecture and operational processes
Data on-boarding techniques such as syslog, DB Connect (dbConnect), Universal Forwarder (UF), HTTP Event Collector (HEC), and custom scripting
Express a working knowledge of Linux to include use cases supporting patching, SSL toolset, capacity planning, routing protocols, and firewall rules
SPL/Dashboard experience in support of user analytics, systems performance, security, and environmental health
Knowledge of Splunk DataModels and their management to include implementation, tuning, and data normalization
Familiarity with Department Information Systems Agency (DISA) Security Technical Implementation Guidelines (STIGs) checklists applicable to each Non-classified or Secret Internet Protocol (IP) Router Network (NIPRNet, SIPRNet) network environment for all Splunk implementations
Implement/create report dashboard designs, automated custom email report notifications, report log data repositories for each environment that are specific to the following audiences: Leadership & Executives; Cybersecurity Staff; and System Administrators
Identify, analyze, define, & coordinate user, client, and stakeholder needs and translate them into technical requirements
Support day-to-day technical communication systems and incident tickets in support of operations
The Splunk Administrator is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies
Qualification
Required
5+ years of overall demonstrated experience in cybersecurity, information assurance or computer science
Minimum 5 years of experience with Splunk
DoD Top Secret Clearance with SCI/ SAP eligibility is required
Bachelors degree from an accredited institution in cybersecurity, information assurance, computer science or a related technical discipline, or the equivalent work experience
DoD 8570.01-M Information Assurance Technical (IAT) Level II
Computing Environment/Operating System (CE/OS) - Linux
Strong customer service experience as this position will require candidate to engage with government leadership
Ability to present ideas clearly through briefings, meetings and interaction with leadership of different skill sets
Ability to work under time constraints and adapt to changes in requirements and new projects
Ability to maintain and upgrade certifications
Ability to assimilate information rapidly, motivated to self-study new requirements
Maintain current industry knowledge of relevant concepts, practices, and procedures
Excellent communication and documentation skills, with strong organizational and collaborative skills
Strong teamwork and engagement as a project team member
Preferred
Candidates with Unix experience are strongly encouraged to apply, as familiarity with Unix-based systems supports many of the core administrative tasks required for managing and optimizing Splunk environments