Job Details
Senior Splunk Integrator
Description
Leidos is seeking a Senior Splunk Integrator to support our Air Force Intranet Control (AFINC) team at Maxwell Gunter AFB in Montgomery, AL. The AFINC Enterprise Network Analysis Team supports the 26 NOS, who requires services and solutions that accomplish and provide enabling capabilities to operate the DoDIN. These capabilities include, but are not limited to, Distributed Network Connectivity, Continuity of Operations, Information Management and Exchange, Standardization, Risk Management, DoD Enterprise Service Management Framework (DESMF), System Administration, Database Management, Account Management, Asset Management and Network Address Management.
Primary Responsibilities
Serve as Splunk engineer, senior leader and/or subject matter expert (SME) responsible for planning, designing, and implementing Splunk across multiple enterprise networks cluster implementations
Assesses current Splunk implementations for each network and recommend changes to distributed deployments to include Indexer Clustering, Search Head Clustering, Forwarders, daily indexing, search volume, number of data sources, number of users, custom apps/dashboards/visualizations
Monitor, troubleshoot, and analyze overall health of Splunk infrastructure
Perform root cause analysis, recommend, and implement tactical and strategic solutions to problems
Develop, update and document Splunk architecture, operational processes, and training materials
Ability to automate global, multi-site solutions with Ansible, Python, and Bash scripting techniques
Experience with various log ingestion methods, new data onboarding and related products, such as Log Agents, syslog, DB Connect (dbConnect), Universal Forwarder (UF) Agent, HTTP Event Collector
Working knowledge of Linux; general networking topics such as SSL, load balancing, routing protocols, firewall rules, and ability to support/interact with McAfee Endpoint Security System (ESS) for RHEL
Document steps required to design/engineer Splunk systems for each network to include virtual/real IP address, Fully Qualified Domain Name (FQDN), DNS entries, Role Based Access Controls (RBAC), service accounts, web certificates, licenses and physical/virtual location of each component
Candidate will oversee activities to include planning, researching, deploying, monitoring, upgrading, patching, and troubleshooting Splunk components spanning a large and complex environment
Basic Qualifications
BS degree and 8 – 12 years of prior relevant experience; additional direct related experience may be considered in lieu of a degree
Candidate must have a minimum of 10+ years of Splunk products experience and/or enterprise monitoring tools experience interacting with 3rd party systems preferably in role(s) such as a system administrator, engineer, developer or architect capacity
Splunk experience with design, implementation and administration in a large-scale environment preferably overseeing daily, weekly, monthly functions and best practices
Identify, analyze, define, & coordinate user, client, and stakeholder needs and translate them into technical requirements
Support day-to-day technical communication systems and incident tickets in support of operations
Candidate should have 4+ years of years of hands-on experience in:
System Integrator and/or administrator for Splunk users, searches/reports, dashboards, systems or 3rd party onboarding log data
Windows OS, UNIX or Linux-based systems support with experience in mid-to-large data center environments and patch/update management
Demonstrated advanced diagnostics, analytical, troubleshooting skills
Preferred system hardening experience
Strongly preferred Splunk Enterprise Security experience
Perform systems analysis, design review, integration of complex system applications
Experience with disaster recovery (DR) - expertise in risk reduction, hot/warm site DR architecture
Experience with physical servers and within virtualized environments such as VMware vSphere’s vCenter Server Appliance, ESXi hosts, virtual machines (VMs), SAN datastores, host bus adapters (HBA) fiber connectivity, and/or VM/Host distributed resource schedules (DRS) groups/rules
Scripting experience with regular expressions and languages such as: Ansible, Bash, JavaScript, HTML, Perl, PowerShell, or Python
CompTIA Security+ ce (continuing education) or (ISC)² CISSP
One Operating System Certification: CompTIA Linux+; Microsoft Technology Associate (MTA)
One Application Certification: Splunk Core Certified User; Splunk Core Certified Power User; Splunk Core Certified Advanced Power User; Splunk Enterprise Certified Admin; Splunk Enterprise Certified Architect; Splunk Certified Developer; Splunk Enterprise Security Certified Admin; Splunk IT Service Intelligence Certified Admin
Secret Clearance
Preferred Qualifications
CompTIA Linux+ or equivalent;
Splunk Core Certified Advanced Power User;
Splunk Enterprise Certified Admin or Splunk Enterprise Security Certified Admin;
Splunk Enterprise Certified Architect or Splunk Certified Developer;
Pay Range:
Pay Range $97,500.00 - $150,000.00 - $202,500.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.