Splunk Engineer (SIEM)

Hybrid in New York, NY, US • Posted 2 hours ago • Updated 2 hours ago
Contract Independent
12 Months
No Travel Required
Hybrid
$85 - $95/hr
Fitment

Dice Job Match Score™

⏳ Almost there, hang tight...

Job Details

Skills

  • Splunk
  • Splunk Enterprise
  • Splunk Cloud
  • Splunk Enterprise Security
  • Splunk ES
  • SPL
  • Splunk Administration
  • Search Head Clustering
  • Indexer Clustering
  • Universal Forwarder
  • Heavy Forwarder
  • Deployment Server
  • Data Onboarding
  • CIM
  • Common Information Model
  • Correlation Searches
  • Dashboards
  • Data Models
  • props.conf
  • transforms.conf
  • SIEM
  • Log Management
  • Threat Detection
  • Incident Response
  • SOAR
  • Splunk Phantom
  • Python
  • PowerShell
  • Bash
  • EDR
  • IDS/IPS

Summary

OZ Solutions Group is a technology services company delivering IT and cybersecurity solutions to government and public sector clients across New York City. We are seeking a hands-on Splunk Engineer (SIEM) for a 12-month contract supporting a highly visible cybersecurity program for a large-scale public sector organization in Lower Manhattan.

This is a hands-on Splunk engineering role — not a SOC analyst or monitoring seat. You will own the engineering, administration, and health of a distributed Splunk environment (cloud and/or hybrid), build the detection and reporting content the citywide Security Operations Center (SOC) relies on, and automate the operational work around it. You should be comfortable whiteboarding and defending an end-to-end Splunk architecture.

Responsibilities:
- Engineer and administer distributed Splunk — search head and indexer clusters, deployment server/deployer, license manager, and heavy/universal forwarder management across a cloud and/or hybrid deployment
- Onboard and normalize log sources (application, database, network, cloud, endpoint) — sourcetype tuning, field extractions, and CIM normalization via props/transforms
- Build detection and reporting content — advanced SPL, data models, tstats, correlation searches, dashboards, reports, and alerts for technical and executive audiences
- Tune detections to reduce false positives and improve fidelity; develop threat-detection and log-correlation use cases aligned to SOC requirements
- Automate operations with Python, PowerShell, and Bash — log-ingestion validation, reporting, and compliance checks; SOAR/playbook automation a plus
- Support incident investigations using Splunk log, endpoint, and network telemetry; contribute to IR documentation and playbooks in coordination with the SOC
- Support endpoint security tooling (EDR/host-based monitoring), hardening and configuration validation, vulnerability-remediation tracking, patch validation, and audit evidence (POA&M)

Required Skills & Experience:
- 5+ years hands-on Splunk Enterprise and/or Splunk Cloud administration and engineering — building and operating a distributed environment, not just searching it
- Indexer/search-head clustering, deployment server and forwarder management, and Splunk configuration (indexes, inputs, props, transforms)
- Strong data onboarding and normalization — getting messy log sources into Splunk, parsed and CIM-compliant
- Fluent in advanced SPL; building dashboards, correlation searches, and alerts
- Scripting/automation in Python, PowerShell, and/or Bash
- Working knowledge of incident response, log correlation, threat detection, IDS/IPS, and EDR/host-based security tools
- Able to work on-site in Lower Manhattan 3 days per week

Preferred:
- Splunk Enterprise Certified Admin or Architect
- Splunk Enterprise Security (ES) content development
- Splunk SOAR / Phantom automation
- CISSP, CEH, GCIH, Security+, or equivalent
- Public sector / regulated-environment experience

Schedule: Monday–Friday, 9:00 AM – 5:00 PM (35-hour work week). Occasional off-hours or weekend support during production cutovers, upgrades, and deployments.

OZ Solutions Group is an equal opportunity employer.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: PTPn031luFwEQBv
  • Position Id: 9036378
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

3d ago

Easy Apply

Contract, Third Party

Depends on Experience

New York, New York

Yesterday

Contract, Third Party

$70 - $80

Hybrid in New York, New York

Yesterday

Easy Apply

Full-time

Depends on Experience

New York, New York

Today

Full-time

USD 147,000.00 - 310,000.00 per year

Search all similar jobs