Haystack
← Back to Jobs
Technology

Cybersecurity Engineer - Richmond, VA

QTech US IncRichmond, VA🇺🇸United StatesPosted 31 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Title: Cybersecurity Engineer
Location: Richmond, VA
Duration: Long Term Contract


Job Summary:
The Virginia Department of Transportation (VDOT) is seeking an experienced Cybersecurity Engineer 3 with strong expertise in Splunk SIEM to develop and implement advanced cyber defense solutions that protect enterprise infrastructure and critical systems. The ideal candidate will be responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while leveraging Splunk Enterprise Security for log analysis, threat hunting, incident response, and security monitoring.
This role requires a highly analytical cybersecurity professional with extensive experience in SIEM operations, SPL query development, threat detection, incident investigation, log integration, and compliance reporting within enterprise environments.

Key Responsibilities:
Monitor network traffic, endpoint logs, and cloud security events to detect suspicious activities and potential cyber threats.
Develop, maintain, and optimize Splunk correlation searches, alerts, dashboards, and detection rules.
Perform proactive threat hunting using Splunk Enterprise Security.
Investigate security incidents and conduct forensic analysis to identify root causes.
Collaborate with infrastructure, networking, and IT teams to contain and remediate security incidents.
Develop and enhance security use cases, detection logic, and response playbooks based on MITRE ATT&CK and threat intelligence.
Integrate new log sources into Splunk while ensuring proper parsing, normalization, and data integrity.
Tune SIEM alerts to reduce false positives and improve threat detection accuracy.
Generate compliance reports and provide SIEM evidence supporting internal and external audits.
Support cybersecurity operations by managing multiple security incidents while maintaining high operational efficiency.
Ensure enterprise cybersecurity solutions are built according to organizational security standards and deployed successfully.

Required Skills:
8+ years of hands-on cybersecurity experience supporting enterprise SIEM platforms.
Strong expertise with Splunk Enterprise Security (SIEM).
Advanced experience writing SPL (Splunk Processing Language) queries.
Experience building, managing, and investigating security threats using Splunk.
Strong knowledge of:
o Network Security
o Firewalls
o Endpoint Detection & Response (EDR)
o Threat Hunting
o Log Analysis
o Incident Response
Experience working with cloud platforms:
o AWS
o Microsoft Azure
o Google Cloud Platform (Google Cloud Platform)
Knowledge of cybersecurity frameworks:
o MITRE ATT&CK
o NIST
o HIPAA
o SOC 2
Experience with SIEM log onboarding, normalization, parsing, and data integration.
Ability to create dashboards, alerts, correlation searches, and detection rules.
Experience producing compliance reports and supporting audit readiness.
Bachelor's Degree in:
o Computer Science
o Cybersecurity
o Information Technology
o Or a related technical discipline.

Preferred Qualifications:
Splunk Core Certified User
Splunk Core Certified Advanced Power User
Experience with enterprise threat intelligence programs.
Experience improving SIEM detection capabilities and reducing alert fatigue.
Knowledge of enterprise cybersecurity architecture and security operations best practices.
Experience supporting government or public sector environments is a plus.

Best Regards:
Tejaswani R.
Phone: +1-
Email:

Skills

AWS
SOC 2
Splunk
Azure
Google Cloud
HIPAA

Similar jobs