drjobs
Splunk Data Analytic Subject Matter Expert
drjobs
Splunk Data Analytic....
drjobs Splunk Data Analytic Subject Matter Expert العربية

Splunk Data Analytic Subject Matter Expert

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs

Job Location

drjobs

Baltimore - USA

Monthly Salary

drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Req ID : 2760445
Please Note: The client is seeking a Splunk Data Analytic Subject Matter Expert to join our team of qualified diverse individuals. This position will be located in Woodlawn MD.

Description:
This Splunk Data Analytic Subject Matter Expert (SME) will provide optimization of data flow using aggregation filters etc. The Splunk Data Analytic SME will be involved in the analysis of unstructured and semistructured data including latent semantic indexing (LSI) entity identification and tagging complex event processing (CEP) and the application of analysis algorithms on distributed clustered and cloudbased highperformance infrastructures. The Subject Matter Expert will exercise creativity in applying nontraditional approaches to largescale analysis of unstructured data in support of highvalue use cases visualized through multidimensional interfaces. Handles processing and index requests against highvolume collections of data and highvelocity data streams. The candidate must have the ability to make discoveries in the world of big data. Requires strong technical and computational skills engineering physics mathematics coupled with the ability to code design develop and deploy sophisticated applications using advanced unstructured and semistructured data analysis techniques and utilizing highperformance
computing environments.

The Splunk Data Analytic Subject Matter Expert must have the ability to utilize advance tools and analytical skills to interpret connect predict and make discoveries in complex data and deliver recommendations for business and analytic decisions. Experience with cyber security application development cyber security data collection tools cyber security information and event management (SIEM) technology supports threat detection compliance and security incident management tools. Through the collection and analysis (both near real time and historical) of security events as well as a wide variety of other event and contextual data sources. The Splunk Data Analytic Subject Matter Expert should be proficient with recognizing and onboarding new data sources into Splunk Splunk Data Pipelines analyzing the data for anomalies and trends and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment editing and maintaining Splunk configuration files and apps.

Duties and Responsibilities:
  • Create a consolidated data set that conforms to the common information model made up of sensor data sources that is already aggregated together and is also already searchable.
  • Develop the capability to aggregate all sensor data results based on two main categories: tangible assets namely hardware software and data and Information Systems groups of assets with a business purpose.
  • Develop the capability to tag new data so that it falls into the ReUsable data assets model so that IO and CDM dashboard can ingest them.
  • Create a way to translate key value pairs from any sensor tools into the format needed to be consumed.
  • Transform already good data into the format needed for ingestion by Xacta.IO and CDM Elastic file.
  • Create data pipeline and create connections between data source(s) and the ReUsable data asset model.
  • Create connection between Splunk and the ReUsable data asset model.
  • Establish Xacta.IO data pipeline connection with the ReUsable data asset model.
  • Establish CDM Elastic data pipeline connection with the ReUsable data asset model.
  • Develop an integrator between Splunk and Xacta.IO and CDM Elastic.
  • Buildout Data Warehouses/ data models:
  • Tag Data
  • Buildout data pipelines in Splunk
  • Establish data pipeline connections
  • Develop Integrators/Integrations (between Splunk DbConnect Splunk Xacta)
  • Aggregate various types of data
  • Create Key Value pairs
  • ETL coding
  • Buildout Dashboards
  • Configure notable event actions action menus and Adaptive Responses.
  • Data onboarding and data ingestion normalization recommendations.
  • Strong knowledge of security risk procedures security patterns authentication technologies and security attack pathologies.
  • Develop evaluate and document specific metrics for management purposes.
  • Create Dashboards to monitor the traffic volumes response times errors and warnings across various data centers.
  • Monitor the web portals log files and databases.
  • Design and Develop Splunk for routine use.
  • Solve complex Integration challenges and debug complex configuration issues.
  • Consult with stakeholders to establish maintain and refresh their strategic direction in cloud adoption.
  • Become knowledgeable on the CDM technical requirements for the federal government s CDM program. Understand your role in CDM activities.
  • Involved in a wide range of security issues including architectures firewalls electronic data traffic and network access.
  • Design manage and maintain enterprise SIEM infrastructure to improve data ingestion processes including architectural work on data pipelines to ensure optimal flow of data.

Requirements

Basic Qualifications:
Minimum knowledge skills abilities needed.
  • Bachelor s degree and 7 years of experience Masters degree and 5 years of experience or 11 years of experience in lieu of a degree
  • At least 4 years experience using customerfocused Splunk Data Pipelining SIEM engineering background
  • At least 4 years experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments
  • At least 4 years of experience with:
  • Indepth knowledge of designing upgrading maintaining and implementing network devices on a largescale enterprise
  • Direct experience with Splunk Engineering and data integration
  • Prior SIEM data modelling experience on similar platform at scale (>50 servers)
  • Scripting and development skills in Python/Perl with deep comprehension of regular expressions
  • Coordination and communication with other remotely deployed team members
  • Developing documentation with processes and procedures
  • Proposing implementing automation features in a large enterprise environment
  • At least 3 years of experience with Linux and SQL/ODBC interfaces
  • At least 2 years of experience with data transport and transformation APIs and technologies such as JSON XML XSLT JDBC SOAP and REST.
  • Hold active Splunk Core Certifications of at least Splunk Architect
  • Minimum of 3 year of experience in developing and tailoring reporting from network security tools.
  • Must be able to obtain and maintain a US Public Trust clearance.

Preferred Qualifications:
Candidates with these skills will be given preferential consideration.
  • Experience with Splunk Common Information Model (CIM) and Enterprise Analytic.
  • Strong problemsolving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Selfstarter with the ability to independently prioritize and complete multiple tasks with little to no supervision.
  • Knowledge of Cloud Services such as AWS Azure Office365.
  • Ability to script in one more of the following computer languages Python Bash Visual Basic or Powershell.
  • Experience in automating Splunk Deployments and orchestration within a Cloud environment.

Basic Qualifications: Minimum knowledge, skills, abilities needed. Requires 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD Cisco Certified Network Engineers must possess a Cisco Certified Network Professional (CCNP) or equivalent level of Cisco Certification. CCNP certification must be the Enterprise Core (EnCor) version. Minimum three (3) years of hands-on network experience configuring routing protocols and switching configuration in medium (One Data Center and 600+ locations) to large enterprise (Two Data Centers and 1000+ locations) networks. Minimum three (3) years of hands-on experience with AWS Networking and possess AWS Advanced Networking Specialty certification. Must be able to obtain a Public Trust clearance Preferred Qualifications: Candidates with these skills will be given preferential consideration. Passed the Cisco Certified Internetworking Expert Written examination within the last one year At least 2 years of experience writing Python scripting language and Regular Expression At Least 3 years of experience implementing Cisco Identity Service Engine (ISE) product in a large multi-data centers and enterprise environment. At least 3 years of experience deploying Cisco Virtual Private Network product such as Cisco ASA and Cisco Wireless LAN in a multi office and large campus environment. At least 3 years of experience working with physical media and equipment associated with each wired and wireless networking. Demonstrate strong oral and written communication skills, with the ability to communicate technical topics to management and non-technical audiences, as well as interface with the customer on a daily basis.

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.