À propos de ce poste Enterprise Logging Solution (ELS) Engineer chez Accenture Federal Services
Supports the Enterprise Logging Solution (ELS)/SIEM environment that provides centralized security monitoring and audit/reporting capabilities to the Agency's System Owners, ISSMs/ISSOs, and the SOC, spanning architecture, implementation, and ongoing operations & maintenance, both on-premise and in the cloud. As an engineer on this task, the role analyzes, develops, and tests proposed ELS/SIEM enhancements, migrates and integrates streaming-ingestion architecture into cloud and on-premise environments, and onboards newly added systems into the ELS/SIEM through a defined data-design, collection, and ingestion-testing process. It builds dashboards for System Owners, ISSM/ISSO, executive management, and developers, and maintains a Master Project Schedule reviewed bi-weekly with Government leadership.Day-to-day O&M responsibilities include tuning correlation rules and signatures, maintaining whitelists/blacklists, and integrating ML/AI capabilities into the Agency's SIEM.
The Work:
- Analyze, develop, and test proposed ELS/SIEM enhancements using vendor/industry best practices; assess current capabilities against the Agency's security/logging regulations at regular intervals and perform gap analyses.
- Migrate/implement ELS/SIEM architecture in cloud and/or on-premise environments; architect and integrate streaming processing solutions for data onboarding/ingestion.
- Develop implementation plans (including communications plans) for approved enhancements; conduct/verify test configurations and present change requests at Change Control Board meetings.
- Onboard newly added systems into the ELS/SIEM (data design requirements, data collection, ingestion scheduling/testing) in coordination with System Owners/ISSOs and the Government ELS Team Lead.
- Create dashboards for System Owners, ISSM/ISSO, executive management, and developers; maintain a Master Project Schedule reviewed bi-weekly with Government leadership.
- Maintain the SIEM's collection/aggregation of IDS, firewall, proxy, DLP, antivirus, cloud log, and vulnerability-scanner data sources; operate streaming ingestion/analysis solutions.
- Develop correlation rules, signatures, and risk-based scoring enhancements; maintain whitelists/blacklists for a better-tuned SIEM.
- Develop, deploy, and/or integrate Machine Learning (ML) and Artificial Intelligence (AI) into the Agency's ELS/SIEM.
- Provide general user support for ELS/SIEM dashboard use (including ISSO audit dashboard functionality) and respond to system-outage/data-feed issues.
Basic Qualifications:
- Minimum 7 years of experience in system administration, database administration, network engineering, software engineering, or software development with a concentration in Cyber Security; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field 5 years of such experience.
Preferred Certifications:
- Splunk Certified Architect
- Splunk Certified Admin
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Connecticut, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Ohio, Vermont, Virginia, Washington, and the District of Columbia. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.