Haystack
← Back to Jobs
Technology
NS

Cybersecurity Engineer

NovaLink SolutionsRichmond, VA🇺🇸United StatesPosted Sep 22, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
17 hours ago
Splunk

Job Description

Job Summary

The Cybersecurity Engineer will play a critical role in protecting enterprise infrastructure by leveraging Splunk Enterprise Security (ES) to monitor, detect, investigate, analyze, and respond to security threats.

The ideal candidate will have strong hands-on experience with Splunk, SIEM, SPL, log analysis, threat hunting, incident response, detection engineering, and security use-case development.

Key Responsibilities

Threat Detection & Monitoring

  • Continuously monitor network traffic, endpoint logs, and cloud security events.
  • Identify anomalous behavior and potential security incidents.
  • Perform proactive threat hunting across enterprise security data.
  • Analyze security events and identify indicators of compromise.

Splunk SIEM Management

  • Administer, configure, maintain, and tune Splunk Enterprise Security.
  • Develop and maintain Splunk correlation searches.
  • Create and tune security alerts and dashboards.
  • Write advanced SPL (Splunk Processing Language) queries.
  • Reduce false positives and improve detection capabilities.
  • Develop and maintain Splunk-based security monitoring and detection use cases.

Incident Response

  • Investigate potential cybersecurity incidents.
  • Perform security event and log analysis.
  • Trace and analyze forensic evidence.
  • Assist with containment, remediation, and recovery activities.
  • Collaborate with IT, infrastructure, endpoint, and network teams during incident response.

Detection & Use Case Development

  • Develop and refine security detection use cases.
  • Create incident response and detection playbooks.
  • Map security detections to MITRE ATT&CK techniques.
  • Leverage threat intelligence to improve detection and response capabilities.

Log Integration

  • Work with infrastructure teams to onboard new security and application data sources into Splunk.
  • Ensure proper log collection, parsing, normalization, and integrity.
  • Troubleshoot data ingestion and logging issues.
  • Maintain consistent security data across the SIEM platform.

Compliance & Reporting

  • Support cybersecurity audits and compliance activities.
  • Collect SIEM control evidence.
  • Generate security and compliance reports.
  • Ensure security monitoring aligns with organizational policies and standards.

Required Skills

  • 8+ years of hands-on cybersecurity experience.
  • 8+ years of experience operating, building, and investigating threats within SIEM/Splunk environments.
  • 8+ years of experience writing SPL (Splunk Processing Language).
  • Strong experience with Splunk Enterprise Security (ES).

Minimum Qualifications

SkillRequirementExperience
Cybersecurity / SIEM / SplunkRequired8+ years
SPL / Splunk Processing LanguageRequired8+ years
Networking / Firewalls / EDR / CloudRequired8+ years
MITRE ATT&CK / Security ComplianceRequired8+ years
Critical Thinking / Problem Solving / CommunicationRequired8+ years
Bachelor's DegreeRequired
Splunk CertificationsHighly Desired

Similar jobs