Job Description
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
Job Summary and Duties
Log Source Validation & Compliance Alignment
Ensure log review SOPs align with STIG and organizational requirements.
Validate log generation, storage, and security configurations across systems.
Confirm system clocks are synchronized to ZULU time for consistent timestamping.
Log Review & Anomaly Detection
Perform regular analysis of log data to identify anomalies, misconfigurations, or potential threats.
Document findings and escalate suspicious activity to incident response teams.
SIEM Integration & Data Feed Management
Integrate DHRA and third-party data feeds into the Splunk SIEM platform.
Deploy and maintain loggers, connectors, and event collectors to ensure data continuity.
Alerting, Correlation & Use Case Development
Develop and tune correlation rules, filters, and alerts to detect significant security events.
Create and maintain use cases to support threat detection and compliance monitoring.
System Maintenance & Component Deployment
Deploy and upgrade Splunk components including ESM, SOAR, and UBA modules.
Coordinate with IT operations and program managers for system modifications and downtimes.
Log Retention, Rotation & Archival Oversight
Monitor log rotation and archival processes to ensure compliance with retention policies.
Conduct regular checks on storage capacity and automate log lifecycle management.
Security Event Analysis & Trend Monitoring
Conduct in-depth analysis of network, system, and application logs.
Identify trends, detect intrusions, and support forensic investigations.
Collaboration & Continuous Improvement
Work with stakeholders to refine logging strategies and respond to audit findings.
Recommend improvements based on policy changes, technology updates, and security needs.
Job Qualifications
Clearance:
- For candidates possessing a security clearance: An active Secret.
This position requires the successful applicant to obtain and maintain the required security clearance or other authorization(s) within the necessary timeframe required by applicable contract(s).
Active DoD 8570 IAT Level III certification (Security+ CE, CISSP, etc.) and relevant Computer Environment Certification
8+ years in cybersecurity operations, with specific expertise in Splunk and UBA and SOAR technologies.
5+ years of experience with an enterprise Logging and Security Information and Event Management (SIEM) solution, to include log collections, management, correlation, aggregation. ingestion, parsing, use case, dashboard, and triggers development.
This is a hybrid (3-days per week onsite) position in Alexandria, Virginia or Seaside, California as required.
Ability to support Cybersecurity reviews, SOP development and maintenance including assisting in the generation of security artifacts, such as security plans, POA&M, and security CONOPS.
Splunk Training and Certification:
- Core Certified Power User ( must have)
- Splunk Enterprise Security Certified Admin
- Splunk Certified Cybersecurity Defense Analyst Splunk
- Splunk Certified Architect
We’re actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you’ll enjoy:
- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.






