Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
17 hours ago
Splunk
Job Description
Job Summary
The Cybersecurity Engineer will play a critical role in protecting enterprise infrastructure by leveraging Splunk Enterprise Security (ES) to monitor, detect, investigate, analyze, and respond to security threats.
The ideal candidate will have strong hands-on experience with Splunk, SIEM, SPL, log analysis, threat hunting, incident response, detection engineering, and security use-case development.
Key Responsibilities
Threat Detection & Monitoring
- Continuously monitor network traffic, endpoint logs, and cloud security events.
- Identify anomalous behavior and potential security incidents.
- Perform proactive threat hunting across enterprise security data.
- Analyze security events and identify indicators of compromise.
Splunk SIEM Management
- Administer, configure, maintain, and tune Splunk Enterprise Security.
- Develop and maintain Splunk correlation searches.
- Create and tune security alerts and dashboards.
- Write advanced SPL (Splunk Processing Language) queries.
- Reduce false positives and improve detection capabilities.
- Develop and maintain Splunk-based security monitoring and detection use cases.
Incident Response
- Investigate potential cybersecurity incidents.
- Perform security event and log analysis.
- Trace and analyze forensic evidence.
- Assist with containment, remediation, and recovery activities.
- Collaborate with IT, infrastructure, endpoint, and network teams during incident response.
Detection & Use Case Development
- Develop and refine security detection use cases.
- Create incident response and detection playbooks.
- Map security detections to MITRE ATT&CK techniques.
- Leverage threat intelligence to improve detection and response capabilities.
Log Integration
- Work with infrastructure teams to onboard new security and application data sources into Splunk.
- Ensure proper log collection, parsing, normalization, and integrity.
- Troubleshoot data ingestion and logging issues.
- Maintain consistent security data across the SIEM platform.
Compliance & Reporting
- Support cybersecurity audits and compliance activities.
- Collect SIEM control evidence.
- Generate security and compliance reports.
- Ensure security monitoring aligns with organizational policies and standards.
Required Skills
- 8+ years of hands-on cybersecurity experience.
- 8+ years of experience operating, building, and investigating threats within SIEM/Splunk environments.
- 8+ years of experience writing SPL (Splunk Processing Language).
- Strong experience with Splunk Enterprise Security (ES).
Minimum Qualifications
| Skill | Requirement | Experience |
|---|---|---|
| Cybersecurity / SIEM / Splunk | Required | 8+ years |
| SPL / Splunk Processing Language | Required | 8+ years |
| Networking / Firewalls / EDR / Cloud | Required | 8+ years |
| MITRE ATT&CK / Security Compliance | Required | 8+ years |
| Critical Thinking / Problem Solving / Communication | Required | 8+ years |
| Bachelor's Degree | Required | — |
| Splunk Certifications | Highly Desired | — |
Similar jobs
- IT
Web Application Firewall Engineer
NewIdeate Technologies LLC
Charlotte, NC🇺🇸Hybrid17 hours agoEngineering - EV
SOC Analyst
NewEvolutyz Corp
United States🇺🇸Remote17 hours agoGoogle CloudTechnology - TG
Security Analyst
NewTalent Groups
Columbia, SC🇺🇸Hybrid17 hours agoMicrosoft OfficeTechnology - SI
Security Architect
NewSerenity Info Tech, Inc.
Richmond, VA🇺🇸On-site17 hours agoJavaScriptTypeScriptPython+14Technology - TE
Information Security Analyst – Agentic AI
NewTEKEngineersInc
Mount Laurel Township, NJ🇺🇸Hybrid17 hours agoStakeholder ManagementTechnology - SY
IT - Security Analyst - Consultant for Onsite Work
NewSyntricate
Columbia, SC🇺🇸On-site17 hours agoMicrosoft OfficeTechnology