Location: Harrisburg, PA
Salary: $90.00 USD Hourly - $95.00 USD Hourly
Description: Role SummaryThe client is seeking a SIEM-focused IT Consultant to provide specialized engineering support for an enterprise security monitoring environment. The consultant will support the design, configuration, integration, optimization, and ongoing operation of a Splunk-based SIEM platform to strengthen threat detection, incident response, log management, and security monitoring capabilities.
Key Responsibilities- Engineer, configure, maintain, and optimise the enterprise SIEM platform, including Splunk and related security technologies.
- Onboard and integrate new data sources; ensure logs are collected, parsed, normalised, indexed, and retained appropriately.
- Develop and maintain correlation searches, alerts, dashboards, reports, detection content, and monitoring rules.
- Integrate SIEM capabilities with cloud platforms, security tools, applications, infrastructure, and enterprise systems.
- Monitor platform health, capacity, availability, and performance while troubleshooting technical issues.
- Tune alerts and detection logic to reduce false positives and improve monitoring effectiveness.
- Support security operations and incident response teams through investigative queries, dashboards, and technical expertise.
- Maintain technical documentation, operational procedures, configurations, and knowledge-transfer materials.
Required Qualifications- 3+ years of professional IT experience supporting SIEM, security engineering, cybersecurity operations, or security monitoring technologies.
- 3+ years of experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
- 3+ years of experience onboarding and integrating security log sources using syslog, APIs, agents, or cloud-native integrations.
- Hands-on experience with SIEM configuration, optimisation, troubleshooting, and platform support.
- Experience creating SPL searches, dashboards, alerts, reports, and correlation searches.
- Experience troubleshooting logging, data-ingestion, integration, and monitoring issues.
- Ability to work onsite in a hybrid environment and attend in-person interviews.
- Must comply with restrictions regarding government-issued equipment usage outside the United States.
Preferred Qualifications- Splunk Enterprise Certified Admin certification.
- Experience supporting large enterprise or government environments.
- Familiarity with NIST and MITRE ATT&CK frameworks.
- Experience supporting SIEM infrastructure upgrades, patching, testing, and implementation activities.
Medical, dental, and vision insurance are available to qualified candidates who meet eligibility requirements.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: This job and many more are available through The Judge Group. Please apply with us today!