← Back to Jobs
Administrative
IT Security SIEM Engineer
Cloud and ThingsNew York, NY🇺🇸United StatesPosted 22 Jul 2026
Why This Role Stands Out
Advance your career in IT security with Cloud and Things, where you'll tackle complex public sector challenges and gain valuable experience with Splunk SIEM administration and threat detection. This hybrid role offers a competitive hourly rate and the chance to contribute to critical cybersecurity initiatives, making it an ideal opportunity for skilled engineers eager to make a significant impact.
Quick Overview
Salary
€50/hr
Work Type
Hybrid
Level
Mid Senior
Job Description
Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environment. Our team is on the forefront of helping to solve the government''s most complex IT challenges. If you are seeking a role that offers the opportunity to work on rewarding projects, consider a career with Cloud and Things.
*This is an exempt position. Salary commensurate with experience*
Job Title: IT Security SIEM Engineer
Location: New York, NY 10038 (Hybrid – 3 days onsite / 2 days remote)
Duration: 12 Months (with potential for extension)
Start Date: August 1, 2026
Hourly Rate: W2 $40–$50/hour (35 hours/week)
Application Deadline: July 24, 2026
Overview:
We are seeking a IT Security SIEM Engineer who will support our NYS client.
This role provides engineering, operational, and administrative support across a complex cybersecurity environment, with primary responsibility for Splunk SIEM administration, log onboarding, threat detection, security monitoring, and incident support.
The engineer will also develop security automation, support endpoint protection and vulnerability remediation activities, and contribute to compliance reporting, audit readiness, and day-to-day security operations.
Duties:
Mandatory Qualifications:
Desirable Qualifications:
Educational & Certification Requirements:
What We Offer:
Ready to make a difference?
We’re eager to connect with qualified candidates committed to delivering results and fostering excellence within client projects.
Cloud and Things complies with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws.
AI-Assisted Resume Evaluation Notice
Cloud and Things – Talent Management
Notice to Candidates
Cloud and Things utilizes artificial intelligence (AI) tools to assist our recruiting team in evaluating candidate applications for streamlining; consistency, efficiency, and thoroughness. All hiring decisions are ultimately made by our human recruiting professionals.
How AI Is Used
Our AI tools assist by:
Cloud and Things Data Handling:
AI Tool Data Processing:
Your Participation
By submitting your application, you acknowledge this notice and consent to AI-assisted evaluation as part of our recruitment process.
*This is an exempt position. Salary commensurate with experience*
Job Title: IT Security SIEM Engineer
Location: New York, NY 10038 (Hybrid – 3 days onsite / 2 days remote)
Duration: 12 Months (with potential for extension)
Start Date: August 1, 2026
Hourly Rate: W2 $40–$50/hour (35 hours/week)
Application Deadline: July 24, 2026
Overview:
We are seeking a IT Security SIEM Engineer who will support our NYS client.
This role provides engineering, operational, and administrative support across a complex cybersecurity environment, with primary responsibility for Splunk SIEM administration, log onboarding, threat detection, security monitoring, and incident support.
The engineer will also develop security automation, support endpoint protection and vulnerability remediation activities, and contribute to compliance reporting, audit readiness, and day-to-day security operations.
Duties:
- Engineer and administer Splunk Enterprise and/or Splunk Cloud environments, including search heads, indexers, deployers, deployment servers, forwarders, and Splunk applications.
- Onboard, parse, normalize, and validate log sources from applications, databases, networks, cloud platforms, infrastructure, and endpoints.
- Develop and maintain complex Splunk searches, dashboards, reports, alerts, and scheduled reporting for technical and executive audiences.
- Analyze log data for anomalies, suspicious activity, operational trends, and potential security incidents.
- Design and refine log-correlation and threat-detection use cases aligned with security operations requirements.
- Tune alerts to reduce false positives and improve detection quality and response efficiency.
- Support daily security monitoring, alert triage, incident analysis, investigations, containment, eradication, and recovery activities.
- Develop and maintain PowerShell, Python, and Bash scripts to automate log-ingestion validation, alert validation, reporting, compliance checks, and security-control verification.
- Support integrations between security tools and automate dashboards and recurring reports where feasible.
- Assist with monitoring endpoint detection and response, antivirus, and host-based security tools; analyze endpoint telemetry for suspicious behavior.
- Support endpoint hardening, security configuration validation, vulnerability remediation tracking, patch validation, and compliance reporting.
- Review infrastructure, firewall, and network security logs in coordination with internal and external security teams.
- Assist with user-access reviews, audit support, security-configuration documentation, architecture diagrams, POA&M tracking, remediation validation, and evidence preparation.
- Gather stakeholder requirements and deliver security reporting, monitoring, and operational solutions.
Mandatory Qualifications:
- 2+ years’ experience administering Splunk Enterprise and/or Splunk Cloud in an enterprise environment.
- 2+ years’ experience onboarding and normalizing diverse log sources and validating log ingestion.
- 2+ years’ experience developing complex Splunk searches, dashboards, reports, alerts, correlation rules, and detection logic.
- 3+ years’ experience analyzing security events, supporting alert triage, and assisting with incident investigations and response activities.
- Knowledge of enterprise logging across applications; web, database, network, cloud, security, and endpoint sources.
- 1+ years’ experience of hands-on scripting experience with PowerShell, Python, and/or Bash for security automation and operational support.
- Understanding of log correlation, threat-detection techniques, and security-monitoring practices.
- Strong analytical, problem-solving, verbal, and written communication skills.
- Ability to work independently, manage assigned tasks, and collaborate with technical and business stakeholders.
Desirable Qualifications:
- Experience with endpoint detection and response, antivirus, or host-based monitoring tools.
- Experience with IDS/IPS technologies and firewall or network-security log monitoring.
- Experience supporting endpoint hardening, vulnerability remediation, patch compliance, access reviews, and audit evidence collection.
- Experience developing or improving security playbooks, POA&M tracking, architecture documentation, or compliance reporting.
- Experience supporting cloud or hybrid SIEM environments and integrations between security platforms.
Educational & Certification Requirements:
- Splunk Enterprise Certified Admin or Splunk Enterprise Certified Architect certification preferred.
- CISSP, CEH, GCIH, Security+, or an equivalent cybersecurity certification preferred.
What We Offer:
- Opportunities to lead impactful transformations in the public sector infrastructure.
- Engagement with high-profile government initiatives, supporting meaningful change.
- A collaborative environment that values ownership, initiative, and continuous learning.
Ready to make a difference?
We’re eager to connect with qualified candidates committed to delivering results and fostering excellence within client projects.
Cloud and Things complies with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws.
AI-Assisted Resume Evaluation Notice
Cloud and Things – Talent Management
Notice to Candidates
Cloud and Things utilizes artificial intelligence (AI) tools to assist our recruiting team in evaluating candidate applications for streamlining; consistency, efficiency, and thoroughness. All hiring decisions are ultimately made by our human recruiting professionals.
How AI Is Used
Our AI tools assist by:
- Analyzing resumes against job requirements
- Supporting our recruiters in candidate data evaluation
- Ensuring consistent review standards across all applications
- Important: AI serves as a support tool only. As noted above, all candidate selection and hiring decisions are made by experienced human recruiters. Your unedited resume will be processed by our AI tools as part of this evaluation.
Cloud and Things Data Handling:
- Your information is processed securely and used exclusively for recruitment purposes
- Cloud and Things may store your resume in our Applicant Tracking System (ATS) indefinitely for future job matching opportunities
- You may opt out of long-term ATS storage by emailing your name and your request to opt out of storing your resume in the ATS to:
- All personal information is handled confidentially in accordance with our privacy policy
AI Tool Data Processing:
- AI processing data is retained for a maximum of 90 days, after which it is deleted
- All data sent to AI tools is encrypted in transit and at rest
- AI tools comply with applicable privacy laws including GDPR and CCPA
- Personal data is anonymized or minimized wherever possible during AI processing
Your Participation
By submitting your application, you acknowledge this notice and consent to AI-assisted evaluation as part of our recruitment process.
Similar jobs
Cyber Operations Plans Analyst with Security Clearance
Department of the Army · Fort Meade, United States
13 minutes agoSoftware Development Manager, Amazon Security Data Engineering
Amazon.com Services LLC · San Luis Obispo, United States
13 minutes ago$184.2k/yrSr. Security Risk Analyst
VC5 Consulting · Houston, United States
32 minutes agoSecurity Operations Center (SOC) Analyst II - Local Candidates only
Fourans · Harrisburg, United States
35 minutes agoApplication Security Engineer - DAST Engineering
Cloud Destinations LLC · Charlotte, United States
35 minutes agoSenior Information Security Engineer - DOWIN Ops with Security Clearance
ASRC Federal · Alexandria, United States
35 minutes ago