About the role
Required Qualifications · Security Clearance: Active Top Secret / Sensitive Compartmented Information (TS/SCI) required at time of hire. · Certification: Active IAT Level II certification (e.g., Security+ CE, CySA+, GSEC, or SSCP) required. · Citizenship: United States Citizenship is required. · Platform Experience: 7+ years of experience with Splunk Enterprise, including architectural design, cluster management, and advanced Search Processing Language (SPL). · AIOps & ITSM: 3+ years of experience implementing AIOps workflows, including integration with enterprise ITSM solutions (ServiceNow) for automated root cause analysis and remediation. · Machine Learning: Proven track record of building, testing, and tuning supervised and unsupervised models within the Splunk MLTK. · Scripting & Automation: Advanced scripting skills for developing custom search commands, API integrations, and automating remediation tasks (e.g., Python). Leadership: Experience leading technical working groups and directing the efforts of adjacent infrastructure and development teams. · Operational Experience: Prior experience working within a DoW/DoD Operations Center (NOC/SOC) or supporting mission-critical systems and networks. · Communication: Must be able to present designs, plans, and analyses of alternatives to technical leadership boards for approvals.
Desired Qualifications · Enterprise Aggregation: Experience aggregating and correlating telemetry from diverse tools, specifically SolarWinds, ServiceNow, and VMware vCenter. · Expert Certification: Splunk Enterprise Certified Architect or Splunk ITSI Certified Admin. · Cloud Observability: Experience with Cloud Native Computing Foundation (CNCF) observability tools in secure hybrid multi-cloud environments (Azure/AWS). · RMF/ATO Knowledge: Understanding of the Risk Management Framework (RMF) and the Authorization to Operate (ATO) process for AI/ML workloads.