Cybersecurity Engineer
Cloud Platforms
Cloud Security
Cyber Forensics
Cybersecurity Tools
Detection Engineering
Endpoint Security
Engineer
Incident Response
Information Security
Investigative Skills
Log Management
Security
Security Compliance
Security Information And Event Management
Security Operations
Security Standards
Siem
Splunk
Splunk Enterprise Security
Job Description
Richmond, VA (onsite) role focused on Splunk SIEM operations, detection engineering, and incident investigation.
Responsibilities
- Continuously review network traffic, endpoint logs, and cloud security events to identify anomalies and potential incidents
- Build, maintain, and tune Splunk correlation searches, alerts, and dashboards to reduce false positives and strengthen detection quality
- Investigate potential incidents using forensic evidence and coordinate with IT and network teams to remediate threats
- Create and refine detection and response playbooks informed by threat intelligence and frameworks such as MITRE ATT&CK
- Partner with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform
- Support audit readiness by collecting SIEM control evidence and producing compliance reports aligned with internal policies and standards
Requirements
- Minimum 8+ years hands-on cybersecurity experience operating, building, and investigating threats within a SIEM or Splunk
- Critical thinking, problem-solving, and communication skills; able to operate calmly under pressure and manage multiple security tickets
- Proficiency writing SPL (Splunk Processing Language)
- Strong understanding of networking, firewalls, EDR, and cloud platforms including AWS, Azure, or GCP
- Knowledge of security frameworks such as MITRE ATT&CK and security compliance standards including NIST, HIPAA, or SOC 2
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
- Relevant certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User (highly preferred)
Technologies
- Splunk SIEM
- Splunk Enterprise Security
- SPL (Splunk Processing Language)
- Splunk correlation searches
- MITRE ATT&CK
- AWS, Azure, GCP
- EDR
- NIST, HIPAA, SOC 2