Splunk Architect, Lead in New York, NY at Booz Allen Hamilton Inc.

Date Posted: 11/13/2018

Job Snapshot

Job Description

Job Number: R0025184

Splunk Architect, Lead

Key Role:
Lead consulting engagements focused on the assessment, design, and implementation of enterprise–scale Splunk solutions by building, operating, and developing for or maintaining Splunk log management infrastructure. Manage Splunk and equivalent hardware infrastructure and oversee production support. Provide architecture–level design to support and operate Splunk using security information and event management (SIEM) or security event management (SEM) best practices and Splunk enterprise security. Design Splunk systems to meet growth while maintaining balance between performance, stability, and agility. Manage customer expectations, onboard data into Splunk, support projects in multi–site or clustered Splunk installations, and assist with the development of advanced reports to meet the requirements of key stakeholders. Conduct research in areas driven by customer use cases, architect and support systems used to configure and deploy enterprise SIEM log management solutions, and develop automation for security tools management. Assist with the automation, deployment, integration, and testing of enterprise systems and services and create and optimize Big Data correlations as a Splunk search language (SPL) expert. These positions may require extensive travel to client sites up to 80% of the time.

Basic Qualifications:
-8+ years of experience with IT
-2+ years of experience as a Splunk administrator or architect
-Experience with customer interaction and onboarding, configuration, and optimization in Splunk
-Experience with using scripting languages to automate tasks and manipulate data
-Experience with working in a large enterprise environment
-Knowledge of enterprise logging, including application, OS, and security technology logging
-Knowledge of regular expressions
-Ability to demonstrate SPL expertise
-Ability to travel up to 80% of the time
-HS diploma or GED

Additional Qualifications:
-2+ years of experience with Splunk, network security, system security, and supporting security information and event management (SIEM)

-Experience with working in a commercial consulting or professional services environment
-Experience with infrastructure management and support and system administration in Windows and UNIX environments
-Experience with enterprise–scale operations and maintenance environments
-Experience with programming a plus
-Experience with Python
-Experience with security tools, including Firewall, IDS, Active Directory, Nmap, Burp, Proxy, or Bro
-Knowledge of networking protocols
-BA or BS degree in CS, IT, or a related field
-Splunk Administrator or Architect Certification

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or veteran status—to fearlessly drive change.

CB15, CMCL

Your Career is Waiting.

Get job alerts. Learn about new work and upcoming events. Share open roles with friends and colleagues.
Our Talent Network is your opportunity hub.


Get Answers and Access.

Need more information? Find it in our FAQs.

Application already in-process? Log in to keep going.