Splunk Detection Engineer

🕒 January 8

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Boston Government Services, LLC (BGS)

Boston Government Services, LLC (BGS)

201 - 500 employees

Founded 2007

🔒 Cybersecurity

🏛️ Government

⚡ Energy

Cybersecurity • Government • Energy

Boston Government Services, LLC (BGS) is a company that provides engineering, technology, and cybersecurity solutions primarily for the federal government and the energy sector. Located in Oak Ridge, TN, BGS offers a range of services including environmental management, nuclear operations, renewable energy, and compliance with cybersecurity standards such as CMMC. The firm prides itself on delivering high-value solutions to complex and highly regulated environments.

📋 Description

• Integrate new data sources, which may include databases, APIs, files, etc. • Validating and creating appropriate configurations for CIM compliant logs • Processing requests from cybersecurity analysts for new detections within Splunk Enterprise Security • Analyzing existing logs to identify poorly formatted logs and potential gaps when implementing new detections • Adding and maintaining threat feeds within Splunk Enterprise Security • Monitoring the performance of and tuning detections • Managing asset and identity inventory within Splunk Enterprise Security • Creating and maintaining new Splunk apps • Recommending additions or changes to Splunk or its data models to meet detection needs • Developing searches, reports, and other functionalities for cyber-based use-cases, including active response, intrusion detection, vulnerability management, and related use cases • Assisting users with creating and optimizing searches and dashboards and mentoring others in good development of said resources • Attend online/Teams meetings with team and others as appropriate • Work with team to provide status on current task, suggest improvements, discuss implementation, etc.

🎯 Requirements

• Significant experience with Splunk and Splunk Enterprise Security • Significant experience with event logging solutions (e.g., Splunk Universal Forwarder, syslog, Cribl) • Experience with ticketing/case management • Experience with Git pipelines • Familiarity with using Linux CLI • Ability to craft queries using common languages; comfort with regex, JSON and APIs; basic scripting in Python/PowerShell/Bash • Excellent analytical, problem-solving, and communication skills both with stakeholders, peers, and internal customers; able to operate under pressure in a shift or on-call environment • Considerable knowledge using and administering Splunk • Staying up to date with the latest cybersecurity threats, vulnerabilities, and best practices • Strong analytical and problem-solving skills • Meticulous attention to detail to ensure thorough assessments and accurate reporting • Excellent written and verbal communication skills to effectively convey findings and recommendations to technical and non-technical stakeholders • Ability to work collaboratively with other cybersecurity professionals, IT staff, and external vendors • Experience and skill in conducting audits or reviews of technical systems • Experience working in a government environment • Experience working in a distributed IT environment • Ability to qualify for HSPD-12 card for use in two-factor authentication

🏖️ Benefits

• Health, Dental, Vision, Life Insurance • Paid Vacation • 401K • Long and Short-Term Disability

Apply Now

Similar Jobs

🕒 January 8

RAYZON GREEN PVT LTD

51 - 200

⚡ Energy

🤝 B2B

Engineer specializing in rooftop solar solutions for the renewable energy sector. Leading EPC projects from design to commissioning in a remote role.

🕒 January 7

ActioNet, Inc.

1001 - 5000

🤖 Artificial Intelligence

🔒 Cybersecurity

AWS/EMR Engineer providing engineering and operational support for secure cloud-based data processing environments. Designing and optimizing scalable compute and storage platforms while maintaining data product compliance.

Apache

AWS

Cloud

Linux

Spark

🕒 January 6

CDW

10,000+ employees

🏢 Enterprise

☁️ SaaS

🔒 Cybersecurity

Manage and maintain IT infrastructure environments for Managed Services customers at CDW. Provide support services including implementation, upgrades, and incident management while ensuring operational stability.

Linux

Unix

🕒 January 6

PerkinElmer

5001 - 10000

🔬 Science

💊 Pharmaceuticals

⚕️ Healthcare Insurance

Project Engineer/Senior Project Engineer at PerkinElmer working on biomanufacturing projects. Delivering high-quality work while supporting business growth through client collaboration and technical delivery.

🕒 January 5

Vannevar Labs

11 - 50

🤖 Artificial Intelligence

🔐 Security

Forward Deployed Engineer handling mission-critical software solutions for national security at Vannevar Labs. Collaborating with operators and analysts to deliver reliable software capabilities.

🇺🇸 United States – Remote

💵 $135k - $205k / year

💰 $12M Series A on 2021-08

⏰ Full Time

🟡 Mid-level

🟠 Senior

👷🏻‍♀️ Engineer

Postgres

React

Redis

TypeScript