Quick Overview
Job Description
Interview Type: In-person
Duties
Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
Onboard new data sources and ensure logs are properly collected, parsed, normalized, indexed, and retained.
Develop and maintain correlation searches, alerts, dashboards, reports, detection rules, and other security monitoring content.
Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and other enterprise systems.
Monitor SIEM platform performance, capacity, availability, and overall health and troubleshoot technical issues.
Tune alerts and detection logic to reduce false positives and improve the effectiveness of security monitoring.
Support SOC analysts and incident response personnel by providing technical expertise, queries, dashboards, and investigative capabilities.
Support upgrades, patches, configuration changes, testing, and implementation of supporting SIEM infrastructure.
Develop and maintain technical documentation operational procedures, system configurations, and knowledge-transfer materials.
Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.
Follow Commonwealth security standards, change-management processes, and applicable cybersecurity policies andr equirements.
Skill | Required / Desired | Amount | of Experience |
| Professional IT experience including at least three years supporting SIEM, security engineering, cybersecurity operations, or security monitoring tech | Required | 3 | Years |
| Required | 3 | Years |
| Demonstrated experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integration | Required | 3 | Years |
| Certifications: Splunk Enterprise Certified Admin Experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security. | Highly desired |
| Experience supporting a large enterprise or government environment. | Highly desired |
| Experience developing SPL searches, dashboards, alerts, correlation searches, and reports. | Highly desired |
| Experience troubleshooting complex SIEM, logging, data ingestion, or integration issues. | Highly desired |
| Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK. | Highly desired |
Similar jobs
- KI
Senior Quality Engineering Test Lead
NewKanshe Infotech
Atlanta, GA🇺🇸On-site21 hours agoJiraEngineering - MS
RTL Design Engineer
NewMarici Solutions
Plano, TX🇺🇸Hybrid21 hours agoAgileVerilogEngineering - TS
Repair Design Engineer\ Stress Engineer
NewTechSynergy Sources, LLC
Wichita, KS🇺🇸Hybrid21 hours agoCATIAGD&TEngineering - V-
CIVIL ENGINEER (LAND DEVELOPMENT)
NewV-CENTRIX-US LLC
Doylestown, PA🇺🇸Hybrid21 hours agoSketchAutoCADCivil 3D+1Engineering - AS
Mechanical Engineering Sales Assistant
ADE Systems, Inc.
United States🇺🇸On-site3 days agoHVACMicrosoft OutlookEngineering - SS
Validation Engineer
NewSIGNin Solutions Inc.
Chandler, AZ🇺🇸Hybrid21 hours agoEngineering - GT
Engineer, Quality
NewGeneris TEK Inc.
Scarborough, ME🇺🇸Hybrid21 hours agoEngineering - ZG
DevSecOps Secuirty Engineer
NewZenox Global, LLC
Washington, DC🇺🇸Hybrid21 hours agoSAFeAgileEngineering - F2
Senior ConnectWise RMM Implementation Engineer
NewF2ONSITE
United States🇺🇸Hybrid21 hours agoEngineering - VI
Senior Cribl Engineer- Full Time Role
NewVisionary Innovative Technology Solutions
Charlotte, NC🇺🇸Hybrid21 hours agoEngineering - V-
CIVIL ENGINEER PROJECT MANAGER (LAND DEVELOPMENT)
NewV-CENTRIX-US LLC
Doylestown, PA🇺🇸Hybrid21 hours agoAutoCADCivil 3DGISEngineering - SI
DevSecOps Engineer - Atlanta, GA(Onsite) - FullTime
NewSage IT Inc
GA🇺🇸On-site21 hours agoEngineering