Haystack
← Back to Jobs
Technology
ME

SIEM Engineer

Merican IncHarrisburg, PA🇺🇸United StatesPosted Oct 9, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Harrisburg, PA, United States
Posted
21 hours ago
Splunk

Job Description

 SIEM Engineer (Splunk)

Location: Harrisburg, PA 17120
Work Arrangement: Hybrid – Onsite 3 days per week
Interview Process: In-person
Employment Type: Contract

 

Job Summary

We are seeking an experienced SIEM Engineer with strong Splunk expertise to support the design, configuration, integration, optimization, and ongoing operation of an enterprise Security Information and Event Management (SIEM) environment.

The ideal candidate will have hands-on experience with Splunk Enterprise and/or Splunk Enterprise Security, security log integration, threat detection, alert development, and security monitoring. This role focuses on strengthening enterprise security visibility, improving threat detection capabilities, supporting incident response, and ensuring reliable log management across a complex IT environment.

Key Responsibilities

  • Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
  • Onboard and integrate new data sources, ensuring logs are properly collected, parsed, normalized, indexed, and retained.
  • Develop and maintain SPL searches, correlation searches, alerts, dashboards, reports, detection rules, and other security monitoring content.
  • Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and enterprise systems.
  • Monitor SIEM platform performance, capacity, availability, and overall health; troubleshoot technical issues as needed.
  • Tune alerts and detection logic to reduce false positives and improve security monitoring effectiveness.
  • Provide technical support to SOC analysts and incident response teams through queries, dashboards, and investigative capabilities.
  • Support platform upgrades, patches, configuration changes, testing, and implementation of SIEM infrastructure.
  • Develop and maintain technical documentation, operational procedures, system configurations, and knowledge-transfer materials.
  • Collaborate with security operations, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.
  • Follow established security standards, change-management procedures, and applicable cybersecurity policies.

Required Qualifications

  • Minimum of 3 years of professional IT experience, including at least 3 years supporting SIEM, security engineering, cybersecurity operations, or security monitoring technologies.
  • At least 3 years of experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
  • At least 3 years of experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integrations.

Preferred Qualifications

  • Splunk Enterprise Certified Admin certification.
  • Experience supporting SIEM solutions in large enterprise or government environments.
  • Hands-on experience developing SPL searches, dashboards, alerts, correlation searches, and reports.
  • Strong troubleshooting skills related to SIEM platforms, log ingestion, data parsing, and system integrations.
  • Familiarity with cybersecurity frameworks and methodologies, including NIST and MITRE ATT&CK.

Ideal Candidate

The ideal candidate is a hands-on SIEM Engineer who can manage and optimize Splunk environments, integrate diverse log sources, develop effective security detections, and collaborate with security operations teams to improve enterprise threat monitoring and incident response capabilities.

Interested candidates: Please share your updated resume highlighting relevant Splunk and SIEM engineering experience

Similar jobs