Cybersecurity Engineer – Splunk SIEM
Location: Richmond, VA Metro Area
Work Arrangement: Hybrid
Employment Type: Contract
Client: Virginia Government Agency
Job Overview
We are seeking an experienced Cybersecurity Engineer with strong expertise in Splunk SIEM and Splunk Enterprise Security (ES) to support advanced cyber defense initiatives.
The Cybersecurity Engineer will be responsible for monitoring, detecting, analyzing, and responding to security threats across enterprise environments. The ideal candidate will have hands-on experience with Splunk queries, log analysis, threat hunting, correlation searches, dashboards, incident response, and security use-case development.
The engineer will work closely with cybersecurity, infrastructure, network, cloud, and IT teams to strengthen security monitoring and improve threat detection capabilities.
Key Responsibilities
Monitor network, endpoint, server, application, and cloud security logs for suspicious and anomalous activity.
Use Splunk Enterprise Security to identify, investigate, and respond to potential security incidents.
Develop, maintain, and tune Splunk correlation searches, alerts, dashboards, and reports.
Write and optimize SPL (Search Processing Language) queries for security monitoring and threat detection.
Perform proactive threat hunting across enterprise security data.
Investigate security alerts and incidents using log analysis and forensic evidence.
Collaborate with infrastructure, networking, cloud, and application teams to contain and remediate security threats.
Develop and enhance security detection use cases based on emerging threats and organizational requirements.
Map detection capabilities to frameworks such as MITRE ATT&CK.
Develop and maintain incident response procedures, detection logic, and security playbooks.
Onboard new security and infrastructure data sources into Splunk.
Configure and troubleshoot log ingestion, parsing, field extraction, and normalization.
Monitor data quality and ensure logs are properly indexed and searchable.
Tune security detections to reduce false positives and improve detection accuracy.
Support security investigations involving endpoints, servers, networks, applications, and cloud environments.
Assist with security audits, compliance activities, and evidence collection.
Generate SIEM reports and documentation aligned with organizational security policies and standards.
Stay current with emerging cyber threats, vulnerabilities, attack techniques, and security technologies.
Required Skills & Experience
5+ years of experience in Cybersecurity, Security Engineering, SIEM, or Security Operations.
Strong hands-on experience with Splunk Enterprise Security (ES).
Strong knowledge of Splunk SPL/Search Processing Language.
Experience developing and tuning correlation searches and security alerts.
Experience creating Splunk dashboards, reports, and security monitoring use cases.
Strong understanding of SIEM concepts and security event monitoring.
Hands-on experience with log analysis and threat hunting.
Experience investigating and responding to security incidents.
Knowledge of MITRE ATT&CK framework and security detection techniques.
Experience onboarding and integrating security data sources into Splunk.
Understanding of log parsing, normalization, field extraction, and data ingestion.
Knowledge of network security, endpoint security, authentication, and cloud security logs.
Strong analytical and troubleshooting skills.
Excellent written and verbal communication skills.
Preferred Qualifications
Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security Certified Admin.
Experience with SOAR platforms and security automation.
Experience with EDR/XDR technologies.
Knowledge of Microsoft Sentinel, QRadar, or other SIEM platforms.
Experience with cloud security monitoring across Azure, AWS, or Google Cloud Platform.
Knowledge of incident response and digital forensics.
Familiarity with security frameworks including NIST, CIS, and MITRE ATT&CK.
Relevant cybersecurity certifications such as CISSP, Security+, CySA+, GCIH, IA.
Technical Skills
SIEM: Splunk, Splunk Enterprise Security
Query Language: SPL
Security: Threat Detection, Threat Hunting, Incident Response, Security Monitoring
Frameworks: MITRE ATT&CK, NIST, CIS
Logging: Windows, Linux, Network, Firewall, Endpoint, Cloud, Application Logs
Cloud: Azure, AWS, Google Cloud Platform
Security Tools: EDR, XDR, SOAR, IDS/IPS, Firewalls
Automation: Security Playbooks, Alert Automation, SOAR
Compliance: Security Audits, SIEM Evidence, Compliance Reporting
Ideal Candidate
The ideal candidate is a hands-on Splunk Cybersecurity Engineer who can independently:
Write complex SPL queries
Build and tune Splunk correlation searches
Develop security dashboards and alerts
Perform threat hunting
Investigate security incidents
Onboard and troubleshoot log sources
Develop detection use cases mapped to MITRE ATT&CK
Reduce false positives
Work with infrastructure and network teams during incident response
Strong Splunk SIEM + SPL + Threat Hunting + Incident Response experience is highly preferred.