Quick Overview
Job Description
Location:Harrisburg,PA
*** In Person Interview*** Long term contract ***Hybrid****(3 Days Per Week Onsite)
Job Description
Provide specialized engineering support for the Commonwealth's Security Information and Event Management (SIEM) environment. The contractor will support the design, configuration, integration, optimization, and ongoing operation of the SIEM platform to strengthen enterprise security monitoring, threat detection, incident response, and log management capabilities. This position reports to the Director and provides hands-on technical support for the SIEM environment. Strategic direction, governance, and overall program oversight remain with the Director.
Duties
- Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
- Onboard new data sources and ensure logs are properly collected, parsed, normalized, indexed, and retained.
- Develop and maintain correlation searches, alerts, dashboards, reports, detection rules, and other security monitoring content.
- Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and other enterprise systems.
- Monitor SIEM platform performance, capacity, availability, and overall health and troubleshoot technical issues.
- Tune alerts and detection logic to reduce false positives and improve the effectiveness of security monitoring.
- Support SOC analysts and incident response personnel by providing technical expertise, queries, dashboards, and investigative capabilities.
- Support upgrades, patches, configuration changes, testing, and implementation of supporting SIEM infrastructure.
- Develop and maintain technical documentation operational procedures, system configurations, and knowledge-transfer materials.
- Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.
- Follow Commonwealth security standards, change-management processes, and applicable cybersecurity policies and requirements.
Skills/Requirements
- Professional IT experience including at least three years supporting SIEM, security engineering, cybersecurity operations, or security monitoring tech Required 3 Years
- Experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security. Required 3 Years
- Demonstrated experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integration Required 3 Years
- Certifications: Splunk Enterprise Certified Admin Highly desired
- Experience supporting a large enterprise or government environment. Highly desired
- Experience developing SPL searches, dashboards, alerts, correlation searches, and reports. Highly desired
- Experience troubleshooting complex SIEM, logging, data ingestion, or integration issues. Highly desired
- Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK. Highly desired
Similar jobs
- ES
AI Solution/Principal Engineer
NewEPAM Systems
United States🇺🇸Hybrid12 hours agoJavaLLMPython+1Technology - OR
Lead Principal Data Center Site Selection Manager
NewOracle Corporation
Nashville, TN🇺🇸$116.6k - $264.1k/yrHybrid12 hours agoOracleStakeholder ManagementTechnology - MS
Staff Mission Lead Systems Engineer - EO / IR Systems
NewMuon Space
United States🇺🇸$177k - $246k/yrHybrid12 hours agoAgileJuliaPythonTechnology - NU
Football Sports Performance Data Analyst
NewNorthwestern University
Evanston, IL🇺🇸$51.4k - $53k/yrHybrid12 hours agoMicrosoft ExcelTechnology - MT
Information Technology Manager
MV Transportation
Kent, WA🇺🇸$141k - $157k/yrHybrid6 days agoSQLSQL ServerActive Directory+1Technology - ES
AI/Machine Learning Engineer
NewEPAM Systems
United States🇺🇸Hybrid12 hours agoSQLMLflowMachine Learning+6Technology - MS
Staff Mission Lead Systems Engineer - RF Systems
NewMuon Space
United States🇺🇸$177k - $246k/yrHybrid12 hours agoAgileJuliaPythonTechnology - AH
Epic Certified EHR Systems Analyst III (EpicCare Ambulatory)
NewAdventist Health
Lincoln, California🇺🇸Remote30 minutes agoTechnology - AH
Epic Certified EHR Systems Analyst III (EpicCare Ambulatory)
NewAdventist Health
Granite Bay, California🇺🇸Remote30 minutes agoTechnology - AM
Technical Writer
NewAir Methods
Englewood, Colorado🇺🇸$64.3k - $80.4k/yrHybrid30 minutes agoAutoCADCADCompliance+2Technology - AH
Epic Certified EHR Systems Analyst III (EpicCare Ambulatory)
NewAdventist Health
Antelope, California🇺🇸Remote30 minutes agoTechnology - AH
Epic Certified EHR Systems Analyst III (EpicCare Ambulatory)
NewAdventist Health
Folsom, California🇺🇸Remote30 minutes agoTechnology