Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Splunk Engineer - Consultant Certified / SOAR Accreditation / TS/SCI CI Poly (R-00052) image - Rise Careers
Job details

Splunk Engineer - Consultant Certified / SOAR Accreditation / TS/SCI CI Poly (R-00052)

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that said outcomes begin and end with our people, and that is what we have built, a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top tier services to our customers. In 2023, True Zero was recognized as a “Best Places to Work” in two categories ("Prosperous and Thriving" ($5MM – $50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)) and in 2022, was recognized as one of Inc. Magazine’s Top 5000 Fastest Growing Companies.


True Zero Technologies is seeking experienced Splunk SOAR engineers or consultants to join our Data Analytics Practice. The position supports the design, implementation, and administration of True Zero's federal customers Splunk SOAR environment, integration with the customers large Enterprise Splunk environment and other various tools. Candidates must possess prior experience working with Splunk SOAR, from both an implementation perspective as well as custom playbook development and workflow defining experience. Candidates with experience in AWS Cloud, Cribl, Syslog, and Axonious is a big plus.


As a TZT consultant, the candidate will receive access to the full knowledge base which is driven by the True Zero community as well as the technical backing of the entire PS team. True Zero encourages collaboration and growth through information sharing and knowledge workshops. The candidate will also have access to our internal Slack channel to stay connected with the team as well as the necessary tools to train, demo, test and grow their professional skills.


Qualification Requirements
  • Minimum 3-5 years of relevant market experience
  • Splunk SOAR Accreditation or 2 years of Splunk SOAR or equivalent SOAR platform experience
  • Ability to showcase strong knowledge of Python language
  • Experience designing and implementing ground up distributed Splunk SOAR installations
  • Experience with advanced configuration of Splunk SOAR
  • Experience maintaining and administering enterprise Splunk SOAR environments
  • Experience developing custom SOAR playbooks, workflows, and configurations
  • Experience integrating SOAR platform with other tools from both a data and automation perspective
  • Enterprise experience working with large teams or collaborative environments
  • Experience working in linux and windows environments, ability to configure:
  • Storage subsystems (I.e. partitioning, Volume Groups, Logical Volumes, etc.)
  • SELinux and FAPolicyd
  • Familiarity with different flavors of Linux distros (RedHat, CentOS, Ubuntu, etc.)
  • File Permission Settings (linux/windows)
  • Excellent written and oral skills, ability to work closely with multiple customers, manage expectations, and track engagement scope.


Preferred Qualifications
  • Splunk Core Consultant Certification
  • Adept at extracting value from data and establishing security use cases
  • Proficient in establishing standardized practices and documentation
  • Possess an understanding of Syslog daemon configuration principles, ideally in Syslog-NG and RSyslog configurations.
  • Cloud experience (AWS, Azure, etc.)
  • Cribl Experience, working with source/destination definitions, pipelines and PACKS, as well as experience writing regular expressions and building routes
  • Experience with Government CDM Programs
  • Familiarity with the aggregation tool Axonius
  • Development and API experience (Python, Perl, XML)
  • Ansible, Spacewalk, and other enterprise automation tool experience.
  • Hardware experience and storage experience (SAN, NAS, etc.)


U.S. Citizenship is required as this is in support of a Federal Customer.


We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:


- Competitive salary, paid twice per month

- Best in class medical coverage

- 100% of medical premiums covered by True Zero

- Company wide new business incentive programs

- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)

- 3 weeks of PTO starting + 11 Paid Holidays Annually

- 401k Program with 100% company match on the first 4%

- Monthly reimbursement of Cell Phone and Home Internet costs

- Paternity/Maternity Leave

- Investment in training and certifications to broaden and deepen your technical skills

True Zero Technologies Glassdoor Company Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
True Zero Technologies DE&I Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of True Zero Technologies
True Zero Technologies CEO photo
Unknown name
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Splunk Engineer - Consultant Certified / SOAR Accreditation / TS/SCI CI Poly (R-00052), True Zero Technologies

Join the innovative team at True Zero Technologies as a Splunk Engineer in Mclean, VA! At True Zero, we believe that the synergy between skilled people and cutting-edge technology leads to superior outcomes for our clients. We're proud to have built a thriving community of passionate professionals dedicated to delivering exceptional services. In this role, you'll support the design, implementation, and administration of our federal customers' Splunk SOAR environments, working closely with their extensive Enterprise Splunk setup. This isn’t just a job; it’s an opportunity to collaborate with fellow experts and make a real impact. Ideal candidates will have 3-5 years of experience in the field and prior expertise with Splunk SOAR, including custom playbook development and serious implementation skills. Your familiarity with AWS Cloud, Syslog, and Axonious will also set you apart! At True Zero, we foster growth and collaboration, offering access to a wealth of resources and an internal Slack channel to keep our team connected. From continuous knowledge-sharing workshops to comprehensive training programs, we provide you with the tools to enhance your professional skills. Plus, enjoy competitive salaries, generous PTO, and full medical coverage – we truly care for our people. If you have the drive to excel and want to contribute to a culture that celebrates success, join us to help redefine what's possible. Experience the True Zero difference today!

Frequently Asked Questions (FAQs) for Splunk Engineer - Consultant Certified / SOAR Accreditation / TS/SCI CI Poly (R-00052) Role at True Zero Technologies
What are the responsibilities of a Splunk Engineer at True Zero Technologies?

As a Splunk Engineer at True Zero Technologies, you will design, implement, and manage Splunk SOAR environments for federal clients. Your day-to-day responsibilities will include developing custom playbooks, administering enterprise environments, integrating with various tools, and collaborating with large teams. You'll be instrumental in enhancing our clients' security operations through effective data management and automation.

Join Rise to see the full answer
What qualifications do I need to become a Splunk Engineer at True Zero?

To become a Splunk Engineer at True Zero Technologies, you'll need 3-5 years of relevant experience, Splunk SOAR Accreditation, and a strong knowledge of Python. Familiarity with cloud platforms like AWS and experience with advanced Splunk SOAR configurations will be highly regarded. Strong written and oral communication skills are also essential as you will work with multiple customers.

Join Rise to see the full answer
What is the work culture like at True Zero Technologies for a Splunk Engineer?

At True Zero Technologies, the work culture for Splunk Engineers is collaborative and community-oriented. We prioritize knowledge sharing and encourage participation in workshops designed to foster professional growth. The team uses internal communication tools like Slack to stay connected and support each other in achieving common goals within a thriving and innovative environment.

Join Rise to see the full answer
Are there opportunities for professional development for Splunk Engineers at True Zero?

Absolutely! True Zero Technologies is committed to the professional growth of our Splunk Engineers. You'll have access to training programs, certification reimbursements, and opportunities to contribute to technical blogs and webinars. We believe investing in our employees' skills leads to better outcomes not just for them but for our clients as well.

Join Rise to see the full answer
What benefits does True Zero Technologies offer Splunk Engineers?

True Zero Technologies offers a competitive benefits package for our Splunk Engineers, including a salary paid bi-monthly, full medical coverage with premiums covered, a generous PTO plan, 401k matching program, monthly reimbursements for communication costs, and paid maternity/paternity leave. We prioritize the well-being and satisfaction of our employees to ensure a great work-life balance.

Join Rise to see the full answer
Common Interview Questions for Splunk Engineer - Consultant Certified / SOAR Accreditation / TS/SCI CI Poly (R-00052)
How do you approach designing and implementing a Splunk SOAR installation?

In preparing to answer this question, emphasize your experience level, the planning process, and collaboration with teams. Discuss your methods for assessing client needs and how you tailor installations to meet their specific security requirements, including scalability and integration.

Join Rise to see the full answer
Can you explain a time when you developed a custom playbook using Splunk SOAR?

Share a specific example highlighting your processes, the challenges faced, and how you overcame them. Illustrate the impact of your custom playbook on improving security responses or automating processes, showcasing your technical ability and problem-solving skills.

Join Rise to see the full answer
What experience do you have with integrating Splunk SOAR with other enterprise tools?

Detail your past experiences with integrations, mentioning specific tools you've worked with and how you ensured seamless data flow and automation. Discuss any challenges you faced to demonstrate your technical acumen and adaptability.

Join Rise to see the full answer
How do you keep up with updates and new features in the Splunk platform?

Emphasize your commitment to continuous learning through professional courses, community forums, and industry publications. Discuss any professional networks or resources you engage with to enhance your understanding of Splunk advancements.

Join Rise to see the full answer
Describe your experience with Python in the context of Splunk SOAR.

Explain your proficiency in Python, providing examples of scripts or applications you've developed for Splunk SOAR functionalities. Highlight how your coding skills facilitated automation or improved incident response.

Join Rise to see the full answer
What troubleshooting steps do you follow when there are issues with Splunk SOAR?

Outline a systematic troubleshooting process you follow, from identifying symptoms to verifying system configurations. Stress the importance of logs, metrics, and collaborative problem solving with team members.

Join Rise to see the full answer
How have you contributed to the security posture of a previous organization using Splunk SOAR?

Discuss specific contributions, such as identifying vulnerabilities, implementing response playbooks, or improving incident detection times. Use metrics if possible to quantify improvements in the security posture.

Join Rise to see the full answer
What is your understanding of SELinux within the context of Splunk SOAR?

Provide a brief overview of SELinux's functionality and security benefits. Illustrate how you have configured SELinux settings in previous roles to enhance the security of Splunk SOAR installations.

Join Rise to see the full answer
What methodologies do you apply for documentation when working on Splunk SOAR projects?

Define your approach to creating and maintaining documentation, emphasizing clarity, consistency, and collaboration. Mention any tools or platforms you use to ensure all team members have access and can contribute.

Join Rise to see the full answer
How do you ensure effective communication when working with clients on Splunk SOAR projects?

Discuss strategies you use to manage client expectations through regular updates, feedback loops, and comprehensive reports. Highlight your ability to translate technical details into user-friendly language.

Join Rise to see the full answer
Similar Jobs
Posted 5 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 7 days ago
Talent Worx Remote No location specified
Posted 3 days ago
Photo of the Rise User
ServiceNow Remote Remote, Los Angeles, California, United States
Posted 8 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
Ramboll Hybrid 333 W Washington St, Syracuse, NY 13202, USA
Posted yesterday
Arcsen Remote No location specified
Posted 4 days ago
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 24, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!