Job Description: SIEM Engineer / Splunk Engineer
Location: Harrisburg, PA 17120
Work Arrangement: Hybrid – Onsite 3 days per week
Interview Type: In-person
Job Summary
We are seeking an experienced SIEM Engineer / Splunk Engineer to provide specialized engineering support for an enterprise Security Information and Event Management (SIEM) environment. The ideal candidate will have hands-on experience with Splunk, security log management, threat detection, alert development, and SIEM platform administration.
The candidate will be responsible for configuring, integrating, maintaining, and optimizing the SIEM platform to enhance enterprise security monitoring, threat detection, incident response, and log management capabilities. This role involves close collaboration with Security Operations Center (SOC) analysts and infrastructure, cloud, networking, and application teams.
Key Responsibilities
-
Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
-
Onboard new data sources and ensure security logs are properly collected, parsed, normalized, indexed, and retained.
-
Develop and maintain correlation searches, alerts, dashboards, reports, detection rules, and security monitoring content.
-
Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and enterprise systems.
-
Monitor SIEM platform performance, capacity, availability, and overall system health.
-
Troubleshoot technical issues related to log ingestion, indexing, data parsing, and platform performance.
-
Tune alerts and detection logic to reduce false positives and improve threat detection effectiveness.
-
Provide technical support to SOC analysts and incident response personnel through queries, dashboards, and investigative capabilities.
-
Support platform upgrades, patches, configuration changes, testing, and implementation of supporting SIEM infrastructure.
-
Develop and maintain technical documentation, operational procedures, system configurations, and knowledge-transfer materials.
-
Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.
-
Follow established security standards, change-management procedures, and applicable cybersecurity policies.
Required Skills and Qualifications
-
Hands-on experience with SIEM platforms, particularly Splunk.
-
Experience with Splunk configuration, administration, monitoring, and troubleshooting.
-
Strong knowledge of security log collection, parsing, normalization, indexing, and retention.
-
Experience developing SIEM searches, alerts, dashboards, reports, and correlation rules.
-
Knowledge of cybersecurity monitoring, threat detection, and security event analysis.
-
Experience integrating SIEM platforms with enterprise applications, infrastructure, cloud platforms, and security tools.
-
Ability to troubleshoot SIEM performance, data ingestion, and system availability issues.
-
Strong analytical, problem-solving, documentation, and communication skills.
-
Ability to collaborate effectively with security operations and technical infrastructure teams.
Preferred Qualifications
-
Experience with Splunk Enterprise Security and Splunk Search Processing Language (SPL).
-
Experience tuning security alerts and improving detection logic.
-
Familiarity with SOC operations and incident response processes.
-
Experience supporting SIEM upgrades, patches, configuration changes, and testing.
-
Knowledge of enterprise cybersecurity standards and change-management processes.
Work Location and Interview Requirements
-
Location: Keystone Building, 5th Floor, Harrisburg, PA 17120.
-
Work Arrangement: Hybrid, with three days onsite per week.
-
Interview Process: In-person interview.
Ideal Candidate Profile
The ideal candidate is a hands-on SIEM or Splunk Engineer with experience maintaining enterprise security monitoring platforms, onboarding log sources, developing detection content, troubleshooting technical issues, and supporting SOC operations.