Peraton is seeking a Splunk Back-End Engineer to build, maintain, and optimize their Splunk platform and security orchestration workflows to ensure reliable data ingestion, perform platform upgrades, automate incident playbooks, and tune search performance for analytics and reporting solutions.
Requirements
- Minimum 5 years hands-on experience administering Splunk Enterprise or Cloud and developing SOAR integrations including Splunk Enterprise/Cloud forwarders, clustering, and indexer configuration
- 5 years’ experience with scripting skills in Python and PowerShell for automation and playbook development
- 3 years’ experience with the following tools: Splunk Enterprise · Splunk Cloud · Splunk SOAR · Universal & Heavy Forwarders · Python · PowerShell · SOAR runbook frameworks · syslog ingestion · AWS S3/SQS ingest pipelines · Docker (for SOAR apps) · Git for configuration management
- Proven ability to optimize SPL performance and scale large ingest pipelines
- In-depth understanding of the Continuous Diagnostics and Mitigation (CDM) program and its phases (vulnerability management, configuration management, identity and access management, and incident response)
- Proficiency in Zero Trust principles, including micro-segmentation, least-privilege access, and continuous verification of users, devices, and services
- Expertise in the NIST Risk Management Framework (RMF) (SP 800-37/SP 800-53), from categorization through monitoring and continuous authorization
Responsibilities
- PLAN AND EXECUTE PLATFORM UPGRADES
- MANAGE DATA INGESTION AND INDEXING
- DEVELOP AND MAINTAIN SOAR PLAYBOOKS
- OPTIMIZE SEARCHES AND REPORTING
- CAPACITY PLANNING & PERFORMANCE TUNING
- DOCUMENTATION & SUPPORT
Other
- Remote position with occasional local on-site meeting support in the Washington, DC, Oklahoma City, OK, or Egg Harbor Township, NJ area required.
- Prior FAA experience is highly desirable.
- Direct collaboration with FAA customers is expected.
- Excellent troubleshooting, documentation, and collaboration skills
- Must be a US Citizen