Home > New York jobs > New York trades & labor jobs

Posted: Monday, January 8, 2018 7:53 PM

Job Description Job Number: R0006818

Booz Allen Hamilton has been at the forefront of strategy and technology for more than 100 years Today, the firm provides management and technology consulting and engineering services to leading Fortune 500 corporations, governments, and not-for-profits across the globe. Booz Allen partners with public and private sector clients to solve their most difficult challenges through a combination of consulting, analytics, mission operations, technology, systems delivery, cybersecurity, engineering and innovation expertise.

Splunk Security Engineer

Key Role:

Develop security-focused content for complex client Splunk deployments, focusing on the creation of complex threat detection logic, dynamic operational dashboards, and data source onboarding and configure and deploy enterprise security, operate Splunk using security information and event management (SIEM) or security event management (SEM), and architect log management or ingestion solutions. Develop automation for security tools management and create customized searches and applications using programming and development expertise, including CSS, HTML, or JavaScript, Python, Shell Scripting, and regular expression. Act as a Splunk Search Language (SPL) expert, developing network or entity-based anomaly detection alerting logic in SPL using the ML toolkit. Conduct research in security principles, host and network-based security technologies, machine learning algorithms, and mitigation methods. Operate, develop for, and maintain the Splunk log management infrastructure, leverage knowledge of several security technologies, information security, and networking, and interact with clients. Assist with the management of Splunk hardware infrastructure, oversee production support, design the Splunk system to meet growth while maintaining a balance between performance, stability, and agility, and develop advanced scripts for the manipulation of multiple data repositories to support analyst requirements. Manage client expectations and develop advanced reports to meet the requirements of key stakeholders, scalable security management tools, and processes. This position may require the ability to travel to locations within the US.

Basic Qualifications:

* 3+ years of experience with IT

* 2+ years of experience with Splunk, network security, system security, and supporting security information and event management (SIEM)

* 1+ years of experience with rule and advanced logic creation in Splunk

* Experience with using scripting languages to automate tasks and manipulate data

* Experience with working in a large enterprise environment

* Knowledge of enterprise logging, including application, OS, and security technology logging

* Knowledge of regular expressions

* Ability to demonstrate SPL expertise

* Ability to travel up to 80% of the time

* BA or BS degree

Additional Qualifications:

* 1+ years of experience with performing hunt activities in an incident response role

* Experience with enterprise-scale operations and maintenance environments

* Experience with programming a plus

* Experience with Python

* Experience with security tools, including Firewall, IDS, Active Directory, Nmap, Burp, Proxy, or Bro

* Knowledge of networking protocols

* BA or BS degree in CS, IT, or related field

* Splunk Admin or Architect Certification

Integrating a full range of consulting capabilities, Booz Allen is the one firm that helps clients solve their toughest problems by their side to help them achieve their missions. Booz Allen is committed to delivering results that endure.

We are proud of our diverse environment, EOE, M/F/Disability/Vet.



Associated topics: forensic, identity, iam, information assurance, malicious, phish, security engineer, security officer, threat, violation


• Location: Manhattan

• Post ID: 153771777 newyork is an interactive computer service that enables access by multiple users and should not be treated as the publisher or speaker of any information provided by another information content provider. © 2018