- Company Name
- Take2 Consulting, LLC
- Job Title
- SIEM Data Onboarding Engineer
- Job Description
-
**Job Title:** SIEM Data Onboarding Engineer
**Role Summary:**
Manage, expand, and optimize the Splunk environment to ensure reliable data ingestion, analysis, and visualization for security and business operations. Drive automation, integration, and best‑practice governance across Linux/Windows platforms while supporting cross‑functional teams.
**Expectations:**
- Maintain high availability and performance of Splunk infrastructure.
- Deliver accurate, timely data pipelines and dashboards.
- Ensure compliance with DoD security standards and maintain active TS/SCI clearance.
- Provide technical guidance, training, and documentation to end‑users.
**Key Responsibilities:**
- Design, deploy, and administer Splunk components (indexers, search heads, forwarders, deployment server).
- Build and sustain Splunk dashboards, SPL queries, alerts, and reports.
- Integrate Splunk with diverse data sources using Cribl pipelines, REST API, and custom scripts.
- Author and maintain configuration files (props.conf, transforms.conf, inputs.conf, outputs.conf) and package Apps/TAs.
- Monitor system health, troubleshoot performance issues, and apply tuning/retention policies.
- Collaborate with stakeholders to capture requirements and deliver Splunk solutions.
- Conduct user training, support, and documentation of Splunk processes.
- Apply DISA STIGs, network fundamentals, and hardening standards in a regulated environment.
**Required Skills:**
- 2+ years Splunk administration, architecture, and REST API automation.
- 2+ years Cribl source/destination/route configuration and pipeline development.
- 2+ years Linux and Windows system administration.
- Proficiency with SPL, regex, and common log formats (syslog, Windows Event, JSON, CSV, XML).
- Scripting: Python, Bash, PowerShell.
- Networking basics: TCP/UDP, TLS, syslog transport, firewall ports.
- Troubleshooting tools: tcpdump, Wireshark, vi/vim, SELinux, setfacl.
- Version control (Git) and automation (Ansible playbooks).
- Strong written and verbal communication.
- Active TS/SCI clearance (polygraph willingness).
**Required Education & Certifications:**
- Associate’s + 5 yr IT experience **or** Bachelor’s + 3 yr IT experience **or** Master’s + 1 yr IT experience **or** 10 yr IT experience (no degree).
- DoD 8570 IAT Level II certification (e.g., Security+ CE, CCNA‑Security, GSEC, SSCP, CySA+, GICSP, CND).
- Must obtain DoD 8570 Cyber Security Service Provider – Infrastructure Support certification before start (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, CND).
District of columbia, United states
On site
Mid level
22-01-2026