the Opportunity
the Opportunity·2 days ago

Cybersecurity engineer

Apply now

Location

onsite, Richmond, VA, United States

Salary

$131k – $139k/yr

Commitment

Full Time

Level

Senior (5+ years)

Required skills

AnalyticsPaaSDevOpsObservabilityComputeComputer VisionDatastoresLogging & MonitoringInfrastructureIaaSBig Data ToolsLog AnalyticsMonitoringLog Management

Job Description

Cybersecurity Engineer – Splunk SIEM

Location: Richmond, VA

Work Arrangement: On-site

Employment Type: Contract

Pay Range: $65–$69/hour W2

Interview: In-person interview required

About the Opportunity

We are seeking an experienced Cybersecurity Engineer with deep hands-on expertise in Splunk Enterprise Security (SIEM) to help protect a large-scale enterprise technology environment. This role is ideal for a cybersecurity professional who enjoys working directly with security events, threat detection, incident investigation, log analysis, and threat hunting. You will use Splunk and other security technologies to identify suspicious activity, improve detection capabilities, investigate incidents, and strengthen the organization's overall security posture.

What You'll Be Doing

  • Monitor network traffic, endpoint logs, cloud security events, and other data sources for suspicious or malicious activity.
  • Use Splunk Enterprise Security to detect, analyze, investigate, and respond to cybersecurity threats.
  • Write and optimize SPL (Splunk Processing Language) queries for security monitoring and threat investigation.
  • Create and tune Splunk correlation searches, alerts, dashboards, and detection rules to improve accuracy and reduce false positives.
  • Perform threat hunting and investigate potential security incidents using log and forensic evidence.
  • Partner with infrastructure, networking, and IT teams to contain and remediate security threats.
  • Develop and refine security detection use cases and incident response playbooks.
  • Leverage MITRE ATT&CK techniques to strengthen threat detection and response capabilities.
  • Onboard and integrate new log and security data sources into the SIEM environment.
  • Ensure proper log parsing, normalization, integrity, and visibility.
  • Support security audits and compliance reporting by collecting SIEM evidence and documentation.

What We're Looking For

  • 8+ years of hands-on cybersecurity experience, including significant experience working with SIEM platforms and Splunk.
  • Strong hands-on experience with Splunk Enterprise Security.
  • Advanced proficiency writing and troubleshooting SPL queries.
  • Experience with threat detection, threat hunting, security monitoring, and incident response.
  • Strong understanding of networking, firewalls, EDR, and endpoint security.
  • Experience with cloud environments such as AWS, Microsoft Azure, or GCP.
  • Knowledge of MITRE ATT&CK and cybersecurity frameworks.
  • Familiarity with security and compliance standards such as NIST, HIPAA, and SOC 2.
  • Strong analytical, troubleshooting, and critical-thinking abilities.
  • Ability to manage multiple security incidents and priorities in a fast-paced environment.
  • Strong written and verbal communication skills.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related discipline.

Preferred Certifications

Relevant Splunk certifications are highly preferred, including:

  • Splunk Core Certified User
  • Splunk Core Certified Advanced Power User
  • Other relevant Splunk or cybersecurity certifications

Ideal Background

The strongest candidates will combine deep Splunk/SIEM expertise with hands-on cybersecurity engineering experience across SPL, threat hunting, incident response, EDR, networking, cloud security, MITRE ATT&CK, and security compliance. This is a hands-on cybersecurity engineering opportunity for someone who wants to play a key role in detecting, investigating, and responding to sophisticated security threats.

Ready to join the team?

Apply now