Summary
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. The Cribl/Splunk Engineer will design, implement, administer, and optimize secure data ingestion pipelines and Cribl/Splunk environments for cybersecurity data. The role also supports troubleshooting, tool integration, SOC collaboration, incident response, compliance, and infrastructure upgrades.
Responsibilities
- Design, develop and implement processes for ingesting data from various sources into Splunk using Cribl Edge and Cribl Cloud
- Configure and manage data inputs to accommodate different types of data sources, including logs, metrics, and events to determine compliance with M-26-14 requirements at the FISMA system boundary level
- Establish and maintain secure and reliable connections between Splunk and external systems or data sources using Cribl Edge and Cribl Cloud
- Monitor, and maintain alerts for failed data inputs
- Deign and recommend Cribl configurations for optimized performance and maximum cost savings
- Design and implement log storage options maximizing cost efficiency while meeting standards of OMB M-26-14
- Oversee the configuration and maintenance of Cribl and Splunk infrastructure, ensuring optimal performance and security of the environment
- Collaborate with cross-functional teams to troubleshoot and resolve issues related to Cribl/Splunk functionality
- Conduct root cause analysis for incidents and implement preventive measures
- Monitor tool health and performance to identify issues, bugs, or potential improvements
- Develop, review, and update existing operational documentation (SOPs, Job Aids, application checklists, playbooks, etc)
- Support system access controls, including Account Management, Access Enforcement, Information Flow Enforcement, Least Privilege, and workflow for all user account requests and account recertifications
- Collaborate with the Security Operations Center (SOC) teams for process optimization, tool tuning, tool integration, information sharing, playbook development, and incident response
- Perform implementation, administration, operations and maintenance, optimization, & integration of cybersecurity tools, technologies, and services
- Conduct regular Cribl/Splunk Enterprise upgrades for worker nodes, deployment servers, heavy forwarders, and syslog servers
Skills
- 4 years of Information Technology Experience
- Bachelor of Science in Computer Science, Information Systems, Mathematics, Engineering, related degree or an additional two (2) years of experience
- 3+ years of Splunk administration or engineering experience
- Proficiency in configuring and managing Splunk inputs, setting up data ingestion pipelines, and establishing system connections
- Knowledge of Splunk's Search Processing Language (SPL), data parsing techniques, and the use of regular expressions for data extraction and transformation
- Skilled in optimizing data pipelines for performance and efficiency, handling large data volumes, and implementing best practices for data integrity and consistency
- Cribl Certified Service Consultant (CCSC) or Cribl Certified Engineer (CC Engineer) preferred
- Cribl Certified Admin (Stream and/or Edge) acceptable
- Splunk Enterprise or Splunk Cloud Certified Admin bonus
- Experience as an engineering team lead (representing the team's work to clients)
- Strong analytical and problem-solving skills, with the ability to effectively prioritize and execute tasks
Qualifications
Must Haves
- 4 years of Information Technology Experience
- Bachelor of Science in Computer Science, Information Systems, Mathematics, Engineering, related degree or an additional two (2) years of experience
- 3+ years of Splunk administration or engineering experience
- Proficiency in configuring and managing Splunk inputs, setting up data ingestion pipelines, and establishing system connections
- Knowledge of Splunk's Search Processing Language (SPL), data parsing techniques, and the use of regular expressions for data extraction and transformation
- Skilled in optimizing data pipelines for performance and efficiency, handling large data volumes, and implementing best practices for data integrity and consistency
- Cribl Certified Service Consultant (CCSC) or Cribl Certified Engineer (CC Engineer) preferred
- Cribl Certified Admin (Stream and/or Edge) acceptable
- Splunk Enterprise or Splunk Cloud Certified Admin bonus
- Experience as an engineering team lead (representing the team's work to clients)
- Strong analytical and problem-solving skills, with the ability to effectively prioritize and execute tasks
Benefits
- 100% remote work
- Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
- Valiant contributes 25% towards Health Coverage for Family and Dependents
- 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
- 100% Paid Certifications
- 401K Matching up to 4%
- Paid Time Off
- Paid Federal Holidays
- Wellness & Fitness Program
- Valiant University – Online Education and Training Portal
- FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
- Referral Bonuses