Splunk Engineer (SIEM)
Why This Role Stands Out
This hands-on Splunk Engineer role offers a fantastic opportunity to own and architect a critical SIEM environment for a major public sector organization, developing essential detection and reporting content. You'll thrive here if you're a skilled engineer eager to deepen your expertise in distributed Splunk administration, log onboarding, and advanced SPL development within a high-impact cybersecurity program. Apply now to contribute to a vital citywide initiative!
Quick Overview
Job Description
OZ Solutions Group is a technology services company delivering IT and cybersecurity solutions to government and public sector clients across New York City. We are seeking a hands-on Splunk Engineer (SIEM) for a 12-month contract supporting a highly visible cybersecurity program for a large-scale public sector organization in Lower Manhattan.
This is a hands-on Splunk engineering role — not a SOC analyst or monitoring seat. You will own the engineering, administration, and health of a distributed Splunk environment (cloud and/or hybrid), build the detection and reporting content the citywide Security Operations Center (SOC) relies on, and automate the operational work around it. You should be comfortable whiteboarding and defending an end-to-end Splunk architecture.
Responsibilities:
- Engineer and administer distributed Splunk — search head and indexer clusters, deployment server/deployer, license manager, and heavy/universal forwarder management across a cloud and/or hybrid deployment
- Onboard and normalize log sources (application, database, network, cloud, endpoint) — sourcetype tuning, field extractions, and CIM normalization via props/transforms
- Build detection and reporting content — advanced SPL, data models, tstats, correlation searches, dashboards, reports, and alerts for technical and executive audiences
- Tune detections to reduce false positives and improve fidelity; develop threat-detection and log-correlation use cases aligned to SOC requirements
- Automate operations with Python, PowerShell, and Bash — log-ingestion validation, reporting, and compliance checks; SOAR/playbook automation a plus
- Support incident investigations using Splunk log, endpoint, and network telemetry; contribute to IR documentation and playbooks in coordination with the SOC
- Support endpoint security tooling (EDR/host-based monitoring), hardening and configuration validation, vulnerability-remediation tracking, patch validation, and audit evidence (POA&M)
Required Skills & Experience:
- 5+ years hands-on Splunk Enterprise and/or Splunk Cloud administration and engineering — building and operating a distributed environment, not just searching it
- Indexer/search-head clustering, deployment server and forwarder management, and Splunk configuration (indexes, inputs, props, transforms)
- Strong data onboarding and normalization — getting messy log sources into Splunk, parsed and CIM-compliant
- Fluent in advanced SPL; building dashboards, correlation searches, and alerts
- Scripting/automation in Python, PowerShell, and/or Bash
- Working knowledge of incident response, log correlation, threat detection, IDS/IPS, and EDR/host-based security tools
- Able to work on-site in Lower Manhattan 3 days per week
Preferred:
- Splunk Enterprise Certified Admin or Architect
- Splunk Enterprise Security (ES) content development
- Splunk SOAR / Phantom automation
- CISSP, CEH, GCIH, Security+, or equivalent
- Public sector / regulated-environment experience
Schedule: Monday–Friday, 9:00 AM – 5:00 PM (35-hour work week). Occasional off-hours or weekend support during production cutovers, upgrades, and deployments.
OZ Solutions Group is an equal opportunity employer.
Similar jobs
Firewall Engineer Principal
SAIC · Suffolk, United States
5 minutes ago$120.0k - $160k/yrSystems Analyst 3 - Databricks Engineer
Rapisource LLC · Austin, United States
5 minutes agoLead LOS Configuration Engineer
Irvine Technology Corporation (ITC) · Irvine, United States
2 hours ago$115k - $135k/yrDatabricks Engineer
Shaarpro · Austin, United States
2 hours agoAutomation Controls Engineer
Shrive Technologies LLC · United States
3 hours agoHardware Test Integration Program Engineer
OSI Engineering, Inc. · Cupertino, United States
3 hours ago$80 - $105/hr