CareFirst BlueCross BlueShield is seeking a Cybersecurity Engineer to develop and implement security solutions and manage security technology systems. The role involves administering user roles, maintaining system performance, and providing technical support related to Splunk operations.
Responsibilities:
- Respond to and resolve customer tickets related to data ingestion issues, search performance, access requests, and platform health
- Administer user roles, access controls, and index permissions in alignment with HIPAA and FedRAMP compliance requirements
- Maintain accurate documentation for all configurations, deployments, and system changes per continuous monitoring obligations
- Perform regular system upgrades and patching to maintain security and performance
- Monitor system performance and troubleshoot issues to ensure optimal functionality of Splunk
- Collaborate with IT and security teams to integrate Splunk with other systems and applications
- Provide technical Splunk support and training to end-users and stakeholders
- Implement and manage data ingestion processes, ensuring data integrity and availability
- Develop and manage Splunk dashboards, reports, alerts, and visualizations
Requirements:
- Bachelor's Degree in Computer Science, Information Technology, or related field OR in lieu of a Bachelor's degree, an additional 4 years of relevant work experience is required in addition to the required work experience
- CISSP (Certified Information Systems Security Professional) and/or CISM Certified Information Security Manager or Certified Ethical Hacker (CEH) or Certified Information Systems Auditor (CISA) upon hire preferred
- 3 years relevant IT security related experience or cybersecurity certification and 1 year related experience required
- Manage Splunk Cloud app and add-on deployments within FedRAMP boundary constraints, coordinating with Splunk support where cloud admin controls are limited
- Respond to and resolve customer tickets related to data ingestion issues, search performance, access requests, and platform health
- Administer user roles, access controls, and index permissions in alignment with HIPAA and FedRAMP compliance requirements
- Maintain accurate documentation for all configurations, deployments, and system changes per continuous monitoring obligations
- Perform regular system upgrades and patching to maintain security and performance
- Monitor system performance and troubleshoot issues to ensure optimal functionality of Splunk
- Collaborate with IT and security teams to integrate Splunk with other systems and applications
- Provide technical Splunk support and training to end-users and stakeholders
- Implement and manage data ingestion processes, ensuring data integrity and availability
- Develop and manage Splunk dashboards, reports, alerts, and visualizations
- Experience with Splunk Enterprise Security (ES)
- Ability to perform risk assessments and investigate cyber security incidents
- Ability to understand vulnerabilities at a technical level
- Knowledge of Information Technology (IT) policy and compliance methodology
- Proficient in hacking techniques
- Strong critical thinking ability and investigative/problem solving skills
- Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence
- Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging
- 3+ years of hands-on Splunk administration experience
- Splunk Certified Cloud Administrator and/or Splunk Enterprise Certified Admin
- Demonstrated experience with Universal Forwarder mass deployment, Heavy Forwarder configuration, and IDM-based data ingest
- Proficiency in SPL and experience building and troubleshooting props/transforms for custom data onboarding
- Proficiency with building custom dashboards to customer requested specifications
- Working knowledge of FedRAMP and HIPAA compliance requirements within a cloud-hosted environment
- Experience managing tickets with clear written communication and timely resolution
- Experience with Cribl Stream or Edge for pipeline management and license optimization