Description:
Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.
Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.
Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.
ROLES AND RESPONSIBILITIES
The Splunk Engineer owns the data and platform craft of the TESIEMS Splunk environment — getting data in cleanly, managing apps and configuration, keeping the data healthy, and hardening and securing the platform — in support of the TSSSOC’s centralized logging mission and OIA’s classified-intelligence operations. Key responsibilities include:
Data Onboarding & Ingest
• Identify, prioritize, and onboard log sources into Splunk; support system owners and data managers across the Department through successful ingest.
• Engineer inputs, parsing (props/transforms), field extraction, and indexing; integrate diverse feeds (networks, infrastructure, bureau sources) reliably.
• Build and maintain reliable, restartable data flows with monitoring and error handling; drive down the onboarding backlog.
Splunk App & Configuration Management
• Manage Splunk apps, add-ons, and knowledge objects; package and deploy configuration via the deployment server / cluster manager.
• Maintain configuration-management discipline across the distributed environment (indexers, search heads, forwarders).
• Develop dashboards, reports, and searches supporting SOC and intelligence use cases.
Data Hygiene & Performance
• Normalize disparate data sets for analytic utility; monitor and improve data quality and coherence across the environment.
• Manage index/storage strategy and retention; optimize ingestion and search performance.
Hardening & Authentication Security
• Harden the Splunk platform and manage secure authentication and access — role-based access control, SSO / LDAP / SAML integration, and least privilege.
• Keep the environment patched and tuned; support vulnerability management and mitigation of the Splunk environment.
• Maintain configuration and security documentation supporting assessment / authorization of the TESIEMS system.
KNOWLEDGE
- Splunk data onboarding: inputs, props.conf/transforms.conf, field extraction, indexing
- Splunk app / add-on and knowledge-object management; deployment server / cluster manager
- Data normalization and data-quality / hygiene practices
- Splunk performance tuning (ingestion and search) and index / storage strategy
- Splunk platform hardening and secure authentication (RBAC, SSO / LDAP / SAML)
- SIEM / SOC operations at enterprise scale
SKILLS
- Reliable data onboarding and normalization across diverse sources
- App and configuration-management discipline across a distributed Splunk deployment
- Dashboard, report, and SPL development
- Ingestion and search performance optimization
- Platform hardening and authentication / access configuration
REQUIRED QUALIFICATIONS
- Bachelor’s degree in Computer Science, Information Technology, or a related field. (Three additional years of relevant experience may substitute for the degree)
- Certifications: None required. Splunk Enterprise Certified Administrator, Splunk Enterprise Certified Architect and Splunk Enterprise Security Certified Administrator preferred
CLEARANCE
- Active Top Secret clearance required
Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.
Requirements: