Remote: N
Salary: $60-70/hr
Location: Dulles, VA
Clearance: Secret
Job Description:
The Continuous Diagnostics and Mitigation (CDM) Data Integration Engineer will assist with the integration of CDM data sensors with the CDM data aggregator. The Engineer will be responsible for working with the product SMEs for Tenable Security Center, Forescout CounterACT, McAfee ePO, and SailPoint IdentityIQ technologies to manage the data connections to Splunk. While these are the currently defined CDM tools, the Engineer will be responsible to integrating any new CDM data sources.
Required Certifications: AWS Certified Security-Specialty Certification or AWS Certified Solutions
Qualifications:
- Must be a US Citizen
- Required Education: Bachelor’s degree in Systems Engineering, Computer Science, Information Systems or related technical field.
- Must have an active SECRET clearance with ability to obtain a TS/SCI
- Must be able to obtain DHS Suitability prior to starting employment
- 8+ years of related experience directly relevant cyber security engineering experience Splunk design/implementation and support effort
- Splunk Power User skills to include:
- Ability to create regex searches
- Ability to create lookups
- Ability to create summary indexes
- Ability to create statistical reports and graphs
- Ability to configure DBConnect app o Ability to configure Tenable Add-On app
- Ability to maintain data models
- CDM Sensor technologies capabilities and data knowledge:
- Tenable Security Center/Nessus – for vulnerabilities and configuration monitoring
- Forescout CounterACT – eyeSight, Splunk HTTP event forwarder, DEX connector
- McAfee ePolicy Orchestrator applications – Application Control and Policy Auditor o SailPoint IdentityIQ
- Communication skills to include:
-
- Updating system documentation
- One-on-one training of product SMEs via virtual and on-premise communications
- Assist large group training of CDM data usage via virtual and on-premise communications
-
Responsibilities:
- Mapping CDM data types to data elements within the CDM sensors
- In collaboration with the product SMEs, determine the best integration method between the CDM sensors and Splunk
- In collaboration with the product SMEs, create the appropriate reports and data exports for their technology
- In collaboration with the Splunk SME, integrate the CDM sensor data into the CDM Splunk repository
- In collaboration with parent CDM organization, create data export processes to allow data to flow from the local CDM data repository to the parent CDM organization
- Support the product SMEs to update CDM sensor data collection and formatting as agreed upon with parent CDM organization
- Validate and monitor data quality within the CDM repository.