iP-Plus Consulting, Inc. CYBERSECURITY ENGINEER 4 – SIEM / SPLUNK ENGINEER Columbus, OH · Richmond, VA · Full time

iP-Plus Consulting is seeking experienced Cybersecurity Engineers to support an upcoming Federal cybersecurity technology program responsible for securing enterprise infrastructure and mission systems within a large federal operational environment. The Cybersecurity Engineer 4 will support enterprise Security Information and Event Management (SIEM) and log management systems. This role focuses on administration, engineering, and enhancement of Splunk Enterprise Security environments used for threat detection, security monitoring, and incident response.

About iP-Plus Consulting, Inc.

iP-Plus Consulting, Inc. is a mission-focused technology and cybersecurity services firm supporting Federal agencies across defense, logistics, and national security sectors. The company specializes in delivering cybersecurity engineering, information assurance, systems integration, and technology modernization solutions that protect critical infrastructure and enable secure mission operations.

Description

Cybersecurity Engineer 4


Location: Onsite in Columbus, OH; or Richmond, VA 


Security Clearance: Secret


Job Description

Cybersecurity Engineer 4 performs a variety of routine project tasks applied to specialized cybersecurity problems. Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to cybersecurity requirements. Analyzes information security requirements. Applies analytical and systematic approaches in the resolution of problems of workflow, organization, and planning. Provides security engineering support for planning, design, development, testing, demonstration, integration of information systems. Analyzes threat information gathered from logs, Intrusion Detection Systems (IDS), intelligence reports, vendor sites, and a variety of other sources. Creates customized dashboards using Security Information and Event Management (SIEM) tool Splunk ES to elevate high threat items to incident responders. Administration knowledge of the Splunk ES and backend database infrastructure related to upgrades and daily maintenance is essential. Provide analysis and make recommendations in line with the roles of CERT Incident Handlers (IH) and site Information Assurance Managers (IAM). Develop ES rules, reports, dashboards, data monitors, active channels, trends and use cases to identify threats and optimize data mining across DLA. Will research, plan, install, configure, troubleshoot, maintain and backup all components in the DLA Splunk Enterprise Log Management (ELM) architecture.


Required Qualifications:

• Seven (7) years of relevant IT experience


• DOD Secret Clearance


• Must possess IT-I Critical Sensitive security clearance or Tier 5 (T5) 


• 8140 Baseline Certification: Primary DCWF Work Role 521: Cyber Defense Infrastructure Support - Proficiency Level: Intermediate

Candidate must possess one of the following certifications:

o CEH, Cloud+, CySA+, PenTest+, SSCP, Security+, and GSEC

Note: higher or advanced GIAC or CISSP concentrations also satisfy the intermediate requirement


• 8140 Baseline Certification for Primary DCWF Secondary DCWF Work Role 451: System Administrator - Proficiency Level: Intermediate

Candidate must possess one the following certifications: 

o CompTIA Security+, CompTIA Cloud+ 

o GIAC Security Essentials (GSEC)


• Computing Environment Certification: Linux+, Splunk Administrator


• Experience creating custom dashboards and reports in Splunk using threat data


• Experience in the integration and sustainment of Splunk Core and Splunk Enterprise Security (ES).