Job Title: Cybersecurity Engineer 3 – Splunk SIEM
Location: Richmond, VA – Onsite
Job Type: Contract
Job Description
We are seeking an experienced Cybersecurity Engineer 3 with strong hands-on expertise in Splunk Enterprise Security (ES), SIEM, threat detection, and incident response. The ideal candidate will be responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while developing and tuning Splunk-based security use cases.
Monitor and analyze security events using Splunk Enterprise Security (ES).
Develop and maintain Splunk SPL queries, correlation searches, alerts, dashboards, and detection rules.
Perform threat hunting and investigate suspicious security activity.
Support incident response, security investigations, and forensic analysis.
Develop security use cases aligned with MITRE ATT&CK and threat intelligence.
Onboard and integrate new security log sources into Splunk.
Perform log parsing, normalization, and data quality validation.
Tune detections and reduce false positives.
Collaborate with infrastructure, network, cloud, and endpoint security teams.
Support cybersecurity audits, compliance activities, and SIEM reporting.
Develop and maintain security monitoring and incident-response documentation.
Strong hands-on experience with Splunk Enterprise Security / Splunk SIEM.
Advanced Splunk SPL query development.
Experience with correlation searches, alerts, dashboards, and detection use cases.
Strong knowledge of SIEM, SOC operations, threat hunting, and incident response.
Experience with MITRE ATT&CK framework.
Experience onboarding and analyzing Windows, Linux, network, endpoint, and cloud security logs.
Knowledge of security monitoring, log management, and event correlation.
Strong analytical and troubleshooting skills.
Excellent communication and documentation skills.
Splunk certifications such as Splunk Enterprise Certified Admin / Architect / Security.
Experience with EDR, IDS/IPS, firewalls, IAM, and cloud security platforms.
Experience developing automated security response/playbooks.
Knowledge of cybersecurity compliance and audit requirements.