410,083open jobs
14,230companies
73,879added this week
Browse all
Location
In office
Employment
Full-Time
Overview
Company
Impact
Profile match
True Zero Technologies is a veteran-owned cybersecurity services firm based in Fairfax, Virginia, founded in 2018. The company provides a broad range of solutions including security engineering, cyber operations, threat intelligence, penetration testing, and managed security services. It operates as a strategic partner to major technology providers and serves federal, state, and commercial clients through various government contract vehicles.

The candidate will be part of a team of Splunk Engineers maintaining various client's Splunk instances with a heavy emphasis on data on-boarding, content development, reporting, and visualizations. All candidates must possess prior Splunk engineering and administration experience, meet the necessary certification prerequisites, and work well in a team environment. Candidates with backgrounds supporting federal customers is a plus.

As a TZT consultant, the candidate will receive access to the full knowledge base which is driven by the True Zero community as well as the technical backing of the entire PS team. True Zero encourages collaboration and growth through information sharing and knowledge workshops. The candidate will also have access to our internal Slack channel to stay connected with the team as well as the necessary tools to train, demo, test and grow their professional skills.

Qualification Requirements

  • US Background Check Required
  • Splunk Consultant Certification
  • Heavy Splunk ES Experience
  • Experience ingesting logs into Splunk via Cribl is required
  • Experience with RBA
  • Develop and Implement Actionable Alerts and Workflow for Splunk as a SIEM (Security Information & Event Management) tool
  • Develop and Implement Apps & Knowledge Objects (KO) like Dashboard, Reports, Data Models
  • Work with the Splunk Architect/Admin to promote private KO to Global KO
  • Assist, and/or train CISO Splunk Engineering team on Data Lifecycle
  • Support Assist, train, and/or host workshops CISO teams and analysts on Searching and Content Development
  • Develop and implement automation to improve efficiency of CISO workflows using Splunk Assist in development of advanced security use cases in Splunk
  • Develop risk rules and risk incident rules to correlate and alert to significant cyber events
  • Develop custom dashboards specific to RBA (Risk Based Alerting) to highlight risk detail, health analysis and risk suppression
  • Configure incident response and remediation workflows for ES around notable events (RBA or otherwise alerted)
  • Develop custom machine learning (ML) models to support anomaly-detection based augmentation of alerting
  • Work with numerous stakeholders to implement & maintain event logging from various operating systems, applications, identity providers, network infrastructure, and cloud service providers. Understanding of network protocols, operating systems, applications, and device event telemetry
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
410,083 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Cyber Threat Hunter 1 hour ago
$115k – $155k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Falls Church
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Apply
$69k – $163k per year (Estimated) • In office • Full-Time • 7+ years exp • Melbourne
Bash
PowerShell
Python
DevOps
Ansible
AWS
Azure
CI/CD
Git
Kubernetes
Splunk
Terraform
Apply
$120k – $135k per year • In office
Perl
PowerShell
Python
SQL
Databases
MySQL
OpenSearch
PostgreSQL
DevOps
Docker
KVM
Splunk
Zabbix
Cybersecurity
Wireshark
Apply
FUSA_Field Engineer 5 hours ago
$80k – $120k per year • In office • 3+ years exp
Perl
PowerShell
Python
Databases
OpenSearch
DevOps
KVM
Splunk
Zabbix
Cybersecurity
Wireshark
Apply
In office • 8+ years exp • PhD
Python
DevOps
AWS
Azure
Dynatrace
GCP
Kubernetes
Self-Healing
Splunk
Apply
$122k – $227k per year (Estimated) • Remote • Full-Time • 5+ years exp
Python
Databases
Chroma
Pinecone
Qdrant
Weaviate
AI/ML
Hugging Face
Keras
LangChain
PyTorch
TensorFlow
DevOps
AWS
Vector
Cybersecurity
STRIDE
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
AWS
Azure
GCP
Cybersecurity
Carbon Black
Crowdstrike
Microsoft Defender
SentinelOne
Tanium
Apply
Remote • Full-Time • 10+ years exp • Bachelor's Degree
C++
Java
Python
Quipper
DevOps
IAM
Quantum
Cirq
Qiskit
Apply
$116k – $241k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Cybersecurity
Zero Trust
Apply
$136k – $244k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
SQL
DevOps
AWS
Azure
Splunk
Cybersecurity
Zero Trust
Analytics
Power BI
Tableau
Apply
See all jobs
This is one of many
410,083 more open roles from verified company boards, updated every day.