1

Splunk Cybersecurity Defense Analyst Jobs in Indiana

Conducts network\system defense analysis and provides recommendations for improvements. Develops and maintains thorough, up-to-date knowledge of cybersecurity threats and incident response best ...

Description & Requirements Shape the future of defense with MANTECH! Join a team dedicated to ... Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career ...

Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics ...

What You Will Do The Cybersecurity Analyst II at EXOS CYBER is the escalation point for the SOC ... Splunk, or QRadar) at the query-and-pivot level. * Familiarity with common log sources such as ...

Coursework in cybersecurity Education: * Associates degree IT, Business, or related field Certifications: * Cyber Defensive Analyst (Basic) Playlist * CEH or equivalent Clearance: * Active Top-Secret ...

Coursework in cybersecurity Education: * Associates degree IT, Business, or related field Certifications: * Cyber Defensive Analyst (Basic) Playlist * CEH or equivalent Clearance: * Active Top-Secret ...

Skilled at teaching security analysis, threat modeling, and defensive strategy implementation ... Familiar with cybersecurity curricula and certification pathways including CompTIA Security+ and ...

next page

Showing results 1-20

Splunk Cybersecurity Defense Analyst information

How does a Splunk Cybersecurity Defense Analyst typically collaborate with other IT and security teams?

A Splunk Cybersecurity Defense Analyst frequently works alongside network administrators, incident response teams, and other security professionals to detect, investigate, and remediate threats. Collaboration often involves sharing threat intelligence, creating automated alerts, and developing dashboards to provide visibility into security events across the organization. Analysts also participate in regular meetings to coordinate response strategies, review incident post-mortems, and ensure that Splunk configurations align with evolving security requirements. This cross-functional teamwork is essential for maintaining an effective and proactive cybersecurity posture.

What are Splunk Cybersecurity Defense Analysts?

Splunk Cybersecurity Defense Analysts are professionals who use the Splunk platform to monitor, analyze, and defend an organization’s digital infrastructure against cyber threats. They collect and interpret security data, investigate incidents, and create alerts and dashboards to detect suspicious activity in real-time. Their work helps organizations respond quickly to threats, ensuring the safety and integrity of sensitive information and systems. These analysts often collaborate with IT and security teams to develop best practices for threat detection and response.

What are the key skills and qualifications needed to thrive as a Splunk Cybersecurity Defense Analyst, and why are they important?

To thrive as a Splunk Cybersecurity Defense Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, typically supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is essential. Strong analytical thinking, problem-solving abilities, and effective communication are important soft skills for collaborating with teams and responding to security incidents. These skills and qualities are critical for quickly identifying, investigating, and mitigating cyber threats to protect organizational assets.

What is the difference between Splunk Cybersecurity Defense Analyst vs Security Operations Center (SOC) Analyst?

AspectSplunk Cybersecurity Defense AnalystSecurity Operations Center (SOC) Analyst
CertificationsSplunk certifications, CompTIA Security+CompTIA Security+, GIAC certifications
Work EnvironmentPrimarily uses Splunk platform for data analysisMonitors security alerts across various tools in a SOC
Industry UsageFinancial, healthcare, tech sectors leveraging SplunkBroadly in all sectors with security teams
Job FocusAnalyzing security data with Splunk, threat detectionMonitoring, incident response, alert management

While both roles focus on cybersecurity, the Splunk Cybersecurity Defense Analyst specializes in using Splunk for data analysis and threat detection, whereas the SOC Analyst performs broader security monitoring and incident response across multiple tools. The roles often overlap but differ in platform focus and scope of responsibilities.

What are popular job titles related to Splunk Cybersecurity Defense Analyst jobs in Indiana? For Splunk Cybersecurity Defense Analyst jobs in Indiana, the most frequently searched job titles are:
What job categories do people searching Splunk Cybersecurity Defense Analyst jobs in Indiana look for? The top searched job categories for Splunk Cybersecurity Defense Analyst jobs in Indiana are:
What cities in Indiana are hiring for Splunk Cybersecurity Defense Analyst jobs? Cities in Indiana with the most Splunk Cybersecurity Defense Analyst job openings:

CSSP Analyst, SME (Team Lead) P41

FEDITC LLC

Indianapolis, IN • On-site

Full-time

Posted 29 days ago


Job description

FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. FEDITC develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country. We are proud & honored to provide these services.
Overview of position:
FEDITC seeks a CSSP Analysis Team Lead to work in the Indianapolis IN area, to direct 24/7 cybersecurity analysis, threat monitoring, and incident response operations for the DFAS Cybersecurity Service Provider (CSSP) program. This position provides subject matter expertise in security event correlation, threat intelligence, and incident handling across all DFAS CCE enclaves including unclassified and classified networks.
An active Top Secret/SCI security clearance and a United States Citizenship is required to be considered for this position.
On-site presence required at designated location
Responsibilities
  • Lead and supervise CSSP Analysis staff delivering 24/7 security event monitoring, analysis, and incident response
  • Direct real-time security event correlation, threat detection, and analysis using SIEM platforms (Splunk, ArcSight, Microsoft Sentinel)
  • Manage cyber security incident response including detection, containment, eradication, and recovery operations
  • Oversee threat intelligence integration, indicator of compromise (IOC) analysis, and threat hunting activities
  • Coordinate internal and external incident reporting per JFHQ-DODIN, Cyber Command, and DFAS requirements
  • Lead audit support, security assessments, and compliance validation activities
  • Direct vulnerability analysis, penetration testing coordination, and remediation tracking
  • Develop and maintain incident response plans, playbooks, and analysis procedures
  • Support CSSP program operations including accreditation documentation and scoring metric compliance
  • Coordinate with DFAS ISSM, security teams, and external stakeholders on security incidents and finding
  • Ensure 100% compliance with DoD CSSP Evaluators Scoring Metrics and reporting requirements

Required Experience/Skills:
  • Minimum 10 years of cybersecurity analysis experience in DoD or Federal environments with increasing responsibility
  • Expert-level knowledge of security event analysis, threat correlation, and incident response methodologies
  • Demonstrated expertise with enterprise SIEM platforms (Splunk, ArcSight, Microsoft Sentinel)
  • Experience with cyber incident handling per NIST 800-61 and DoD incident reporting requirements
  • Strong knowledge of threat intelligence, malware analysis, and forensic investigation techniques
  • Experience with vulnerability management programs (ACAS, Nessus) and penetration testing
  • In-depth understanding of NIST 800-53, DISA STIGs, and DoD cybersecurity frameworks
  • Knowledge of DoD CSSP requirements, evaluations, and JFHQ-DODIN reporting
  • Proven ability to lead security analysis teams in high-pressure 24/7 operational environments
  • Ability to support COOP exercises and emergency operations

Preferred Qualifications:
  • GIAC certifications (GCIA, GCIH, GCFA, GNFA)
  • SANS DFIR certifications or equivalent
  • Experience with classified network (JWICS) security operations
  • Splunk Certified Security Analyst or equivalent
  • Experience leading threat hunting programs
  • DFAS or DoD financial system security operations experience

Certifications:
  • Cyber Defensive Analyst (Advanced) Playlist and CySA+ (or equivalent per 511 A)
  • Computing Environment (CE) certification required for privileged access roles
  • Must obtain and maintain all mandatory DoD 8140 certifications

Education:
  • BA/BS Degree

Clearance:
  • Active Top Secret/ SCI clearance is required.
  • Must be a United States Citizen and pass a background check.
  • Maintain applicable security clearance(s) at the level required by the client and/or applicable certification(s) as requested by FEDITC and/or required by FEDITC'S Client(s)/Customer(s)/Prime contractor(s).

FEDITC, LLC. is committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment. We do not employ AI tools in our decision-making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, FEDITC, LLC. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws. Our commitment to non-discrimination in employment extends to every location in which our company operates.