Job: SIEM Engineer – Splunk
Client: Commonwealth of Pennsylvania
Location: Harrisburg, PA 17120
Work Model: Hybrid – Onsite 3 days per week
Interview: In-person
Job Summary
We are looking for a SIEM Engineer with strong Splunk experience to support enterprise cybersecurity monitoring, threat detection, log management, and incident response. The candidate will be responsible for configuring, maintaining, and optimizing the SIEM platform and integrating security log sources across enterprise systems.
Key Responsibilities
* Configure, maintain, and optimize Splunk Enterprise and Splunk Enterprise Security.
* Onboard and integrate log sources using Syslog, APIs, agents, and cloud integrations.
* Develop SPL searches, dashboards, alerts, reports, and correlation searches.
* Monitor SIEM performance, data ingestion, capacity, and system health.
* Troubleshoot logging, integration, and data ingestion issues.
* Tune alerts and detection rules to reduce false positives.
* Support SOC analysts and incident response teams with security investigations.
* Perform SIEM upgrades, patches, testing, and configuration changes.
* Maintain technical documentation and operational procedures.
* Collaborate with security, cloud, networking, infrastructure, and application teams.
* Follow cybersecurity policies, security standards, and change-management procedures.
Required Skills
* 3+ years of IT experience in SIEM, security engineering, cybersecurity operations, or security monitoring.
* 3+ years of experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
* 3+ years of experience onboarding and integrating security log sources using Syslog, APIs, agents, or cloud-native integrations.
Preferred Skills
* Splunk Enterprise Certified Admin certification.
* Experience in large enterprise or government environments.
* Strong experience with SPL searches, dashboards, alerts, correlation searches, and reports.
* Experience troubleshooting SIEM, logging, data ingestion, and integration issues.
* Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK.
Important Requirements
* Must be able to work onsite in Harrisburg 3 days per week.
* Must be available for an in-person interview.
* Strong hands-on Splunk and SIEM engineering experience is essential.