Lead Security Engineer Ii, Splunk Security Content Visualization Expert (secret Clearance)

This role focuses on optimizing Splunk dashboards, applications, and alerts for Security Operations Centers (SOCs) to enhance performance and maturity. Responsibilities include developing advanced reporting and visualizations, building and tuning security content, performing advanced searches in SIEM environments, analyzing security log data, and developing custom SPL. The role also involves mentoring junior analysts and identifying indicators of compromise. It requires experience with Splunk, SIEM environments, and security log analysis, with a strong emphasis on security content development and SOC operations.

What you'd actually do

  1. Design, customize, configure, and optimize Splunk dashboards, applications, alerts, and visualizations to improve SOC performance and maturity.
  2. Develop advanced reporting and visualizations to support SOC operations and stakeholder requirements.
  3. Build, test, document, implement, and tune security content across the full lifecycle, including data models, dashboards, correlation logic, searches, and alert notifications.
  4. Perform advanced searches and analysis in large-scale SIEM environments.
  5. Analyze, trend, and filter security log data from multiple sources, including firewalls, IDS/IPS, hosts, load balancers, and other security and monitoring tools.

Skills

Required

  • Splunk dashboard design and optimization
  • Splunk application development
  • Splunk alert configuration
  • Security Operations Center (SOC) performance improvement
  • Advanced reporting and visualization development
  • Security content lifecycle management (build, test, document, implement, tune)
  • Data model development
  • Correlation logic development
  • Search development
  • Alert notification development
  • Advanced SIEM environment analysis
  • Security log data analysis
  • Firewall log analysis
  • IDS/IPS log analysis
  • Host log analysis
  • Load balancer log analysis
  • Custom SPL development
  • Macros
  • Lookups
  • Regex
  • Network-based logic
  • SOP development and implementation
  • Mentoring junior analysts
  • Indicator of Compromise (IOC) identification
  • Network traffic indicator analysis
  • Lateral movement detection
  • Enterprise logging use cases
  • Application log analysis
  • Operating system log analysis
  • Security device log analysis
  • Bachelor's Degree
  • Active Secret Clearance
  • Ability to work onsite in Herndon, VA
  • Ability to travel 15%
  • CISSP, GCIH, GCFA, GPEN, GWAPT, GCIA certification

Nice to have

  • Ability to work independently
  • Team collaboration
  • Effective written and verbal communication skills
  • Meticulous attention to detail
  • Quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks
  • Strong interpersonal skills
  • Professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

What the JD emphasized

  • Active Secret Clearance required
  • Ability to work onsite in Herndon, VA up to 3 days a week
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.