DescriptionThank you for considering IT Concepts dba Kentro where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers missions fostering professional growth and making a positive impact on our communities.
By joining our supportive community you will find that Kentro is dedicated to your personal and professional development. Together we can drive meaningful change spark innovation and achieve extraordinary milestones.
Kentro is seeking a highly skilled and motivated SIEM/Data Integration Engineer to design build and manage the critical telemetry pipeline for a landmark Zero Trust initiative at U.S. Special Operations Command (USSOCOM). This role is the lynchpin for security visibility ensuring that the high-volume complex data generated by modern security tools is intelligently processed and delivered to security analysts in a timely cost-effective and usable format.
Your primary responsibility will be to architect and operate the Cribl Stream environment creating an intelligent data pipeline that sits between the cloud-native security tools (Microsoft Purview Microsoft Sentinel) and the enterprise Splunk SIEM. You will be the technical expert responsible for ingesting filtering transforming enriching and routing massive streams of security data across the NIPR SIPR and Top Secret networks. By optimizing the flow of data you will also play a crucial role in managing the performance and cost of the enterprise SIEM ensuring the long-term sustainability of the Commands security monitoring capabilities.
Responsibilities:
- Telemetry Pipeline Architecture: Design deploy and maintain the Cribl Stream infrastructure ensuring high availability and performance for the security telemetry pipeline across all network enclaves.
- Data Routing & Filtering: Develop and manage Cribl Stream routes to process security data implementing rules to filter out low-value logs and route high-value telemetry to Splunk and Microsoft Sentinel.
- Data Integration: Configure data source collectors to ingest logs from Microsoft Purview Microsoft Sentinel and on-premise security tools utilizing APIs (such as Microsoft Graph) to pull compliance data.
- Log Enrichment: Enrich security logs in-flight by adding valuable context such as correlating user identity information with network events or adding geolocation data before the data reaches the SIEM.
- SIEM Optimization: Proactively reduce Splunk ingestion volume and license costs by strategically filtering and summarizing data within Cribl Stream while ensuring that the data delivered aligns with the Splunk Common Information Model (CIM).
Location: Onsite in Tampa FL
Requirements- Senior Level: Master of Science (MS) degree in Systems Engineering Computer Science Cybersecurity Electrical Engineering or a related technical field.
- Senior Level: 10 years of related technical experience.
- Splunk Expertise: Extensive (5 years) experience as a Splunk administrator or engineer with deep expertise in data onboarding parsing index-time processing and search performance optimization.
- Pipeline Management: Direct hands-on experience (2 years) designing and managing a telemetry pipeline or log routing solution with a strong preference for Cribl Stream.
- Scripting & Automation: Proficiency in scripting using languages such as Python or PowerShell for data manipulation and API interaction.
- Data Parsing: Strong understanding of regular expressions (Regex) for complex data parsing extraction and normalization.
Preferred Experience & Skills (Nice-to-Haves):
- Cribl Certified Observability Engineer (CCOE) certification.
- Splunk certifications such as Splunk Certified Architect or Enterprise Security Certified Admin.
- Hands-on experience with Microsoft Sentinel and Microsoft Purview as data sources.
- Experience working in a large complex DoD or USSOCOM environment.
Certifications:
- Required: CompTIA Security CE CompTIA CySA or a higher-level certification to meet DoD 8570 IAT Level II requirements.
- Preferred: Splunk Core Certified Advanced Power User Splunk Enterprise Certified Admin/Architect or Cribl CCOE certifications.
Clearance:
- Active Top Secret clearance with SCI eligibility.
BenefitsThe Company
We believe in generating success collaboratively enabling long-term mission success and building trust for the next challenge. With you as our partner lets solve challenges think innovatively and maximize impact. As a valued member of our team you have the unique opportunity to work in a diverse range of technology and business career paths all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork dedication and excellence.
We hold three ISO certifications (27001:-1::2015) and two CMMI ML 3 ratings (DEV and SVC).
Industry Recognition
Growth Inc 5000s Fastest Growing Private Companies DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies Top Performing Small Technology Companies in Greater D.C.
Culture Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work Corporate Diversity Index Winner Mid-Size Companies Companies Owned by People of Color; Department of Labors HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award
Benefits
We offer competitive benefits package including paid time off healthcare benefits supplemental benefits 401k including an employer match discount perks rewards and more. We invest in our employees Every employee is eligible for education reimbursement for certifications degrees or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course complete a certification or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.
We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities virtual and in-person e.g. we host happy hours holiday events fitness & wellness events and annual alignment with our commitment to our communities we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative innovative and happy.
Commitment Equal Opportunity Employment & VEVRAA
Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability status as a protected veteran or any other status protected by applicable federal state or local law.
Kentro is strongly committed to compliance with VEVRAA and other applicable federal state and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.
As part of our VEVRAA compliance efforts Kentro has established an equal opportunity plan outlining our commitment to recruiting hiring and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.
We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.
Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees including protected veterans are treated with dignity respect and fairness.
How to Apply
To apply to Kentro Positions- Please click on the: Apply for this Job button at the bottom of this Job Description or the button at the top: Application. Please upload your resume and complete all the application steps. You must submit the application for Kentro to consider you for a position. If you need alternative application methods please email and request assistance.
Accommodations
To perform this job successfully an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations please email .
Required Experience:
Senior IC
DescriptionThank you for considering IT Concepts dba Kentro where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers missions fostering professional growth and making a positive impact on our communities. ...
DescriptionThank you for considering IT Concepts dba Kentro where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers missions fostering professional growth and making a positive impact on our communities.
By joining our supportive community you will find that Kentro is dedicated to your personal and professional development. Together we can drive meaningful change spark innovation and achieve extraordinary milestones.
Kentro is seeking a highly skilled and motivated SIEM/Data Integration Engineer to design build and manage the critical telemetry pipeline for a landmark Zero Trust initiative at U.S. Special Operations Command (USSOCOM). This role is the lynchpin for security visibility ensuring that the high-volume complex data generated by modern security tools is intelligently processed and delivered to security analysts in a timely cost-effective and usable format.
Your primary responsibility will be to architect and operate the Cribl Stream environment creating an intelligent data pipeline that sits between the cloud-native security tools (Microsoft Purview Microsoft Sentinel) and the enterprise Splunk SIEM. You will be the technical expert responsible for ingesting filtering transforming enriching and routing massive streams of security data across the NIPR SIPR and Top Secret networks. By optimizing the flow of data you will also play a crucial role in managing the performance and cost of the enterprise SIEM ensuring the long-term sustainability of the Commands security monitoring capabilities.
Responsibilities:
- Telemetry Pipeline Architecture: Design deploy and maintain the Cribl Stream infrastructure ensuring high availability and performance for the security telemetry pipeline across all network enclaves.
- Data Routing & Filtering: Develop and manage Cribl Stream routes to process security data implementing rules to filter out low-value logs and route high-value telemetry to Splunk and Microsoft Sentinel.
- Data Integration: Configure data source collectors to ingest logs from Microsoft Purview Microsoft Sentinel and on-premise security tools utilizing APIs (such as Microsoft Graph) to pull compliance data.
- Log Enrichment: Enrich security logs in-flight by adding valuable context such as correlating user identity information with network events or adding geolocation data before the data reaches the SIEM.
- SIEM Optimization: Proactively reduce Splunk ingestion volume and license costs by strategically filtering and summarizing data within Cribl Stream while ensuring that the data delivered aligns with the Splunk Common Information Model (CIM).
Location: Onsite in Tampa FL
Requirements- Senior Level: Master of Science (MS) degree in Systems Engineering Computer Science Cybersecurity Electrical Engineering or a related technical field.
- Senior Level: 10 years of related technical experience.
- Splunk Expertise: Extensive (5 years) experience as a Splunk administrator or engineer with deep expertise in data onboarding parsing index-time processing and search performance optimization.
- Pipeline Management: Direct hands-on experience (2 years) designing and managing a telemetry pipeline or log routing solution with a strong preference for Cribl Stream.
- Scripting & Automation: Proficiency in scripting using languages such as Python or PowerShell for data manipulation and API interaction.
- Data Parsing: Strong understanding of regular expressions (Regex) for complex data parsing extraction and normalization.
Preferred Experience & Skills (Nice-to-Haves):
- Cribl Certified Observability Engineer (CCOE) certification.
- Splunk certifications such as Splunk Certified Architect or Enterprise Security Certified Admin.
- Hands-on experience with Microsoft Sentinel and Microsoft Purview as data sources.
- Experience working in a large complex DoD or USSOCOM environment.
Certifications:
- Required: CompTIA Security CE CompTIA CySA or a higher-level certification to meet DoD 8570 IAT Level II requirements.
- Preferred: Splunk Core Certified Advanced Power User Splunk Enterprise Certified Admin/Architect or Cribl CCOE certifications.
Clearance:
- Active Top Secret clearance with SCI eligibility.
BenefitsThe Company
We believe in generating success collaboratively enabling long-term mission success and building trust for the next challenge. With you as our partner lets solve challenges think innovatively and maximize impact. As a valued member of our team you have the unique opportunity to work in a diverse range of technology and business career paths all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork dedication and excellence.
We hold three ISO certifications (27001:-1::2015) and two CMMI ML 3 ratings (DEV and SVC).
Industry Recognition
Growth Inc 5000s Fastest Growing Private Companies DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies Top Performing Small Technology Companies in Greater D.C.
Culture Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work Corporate Diversity Index Winner Mid-Size Companies Companies Owned by People of Color; Department of Labors HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award
Benefits
We offer competitive benefits package including paid time off healthcare benefits supplemental benefits 401k including an employer match discount perks rewards and more. We invest in our employees Every employee is eligible for education reimbursement for certifications degrees or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course complete a certification or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.
We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities virtual and in-person e.g. we host happy hours holiday events fitness & wellness events and annual alignment with our commitment to our communities we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative innovative and happy.
Commitment Equal Opportunity Employment & VEVRAA
Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability status as a protected veteran or any other status protected by applicable federal state or local law.
Kentro is strongly committed to compliance with VEVRAA and other applicable federal state and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.
As part of our VEVRAA compliance efforts Kentro has established an equal opportunity plan outlining our commitment to recruiting hiring and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.
We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.
Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees including protected veterans are treated with dignity respect and fairness.
How to Apply
To apply to Kentro Positions- Please click on the: Apply for this Job button at the bottom of this Job Description or the button at the top: Application. Please upload your resume and complete all the application steps. You must submit the application for Kentro to consider you for a position. If you need alternative application methods please email and request assistance.
Accommodations
To perform this job successfully an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations please email .
Required Experience:
Senior IC
View more
View less