CybersecurityJobs.io
← Back to all jobs

Job Description

Richmond, VA (onsite) role focused on Splunk SIEM operations, detection engineering, and incident investigation.

Responsibilities

  • Continuously review network traffic, endpoint logs, and cloud security events to identify anomalies and potential incidents
  • Build, maintain, and tune Splunk correlation searches, alerts, and dashboards to reduce false positives and strengthen detection quality
  • Investigate potential incidents using forensic evidence and coordinate with IT and network teams to remediate threats
  • Create and refine detection and response playbooks informed by threat intelligence and frameworks such as MITRE ATT&CK
  • Partner with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform
  • Support audit readiness by collecting SIEM control evidence and producing compliance reports aligned with internal policies and standards

Requirements

  • Minimum 8+ years hands-on cybersecurity experience operating, building, and investigating threats within a SIEM or Splunk
  • Critical thinking, problem-solving, and communication skills; able to operate calmly under pressure and manage multiple security tickets
  • Proficiency writing SPL (Splunk Processing Language)
  • Strong understanding of networking, firewalls, EDR, and cloud platforms including AWS, Azure, or GCP
  • Knowledge of security frameworks such as MITRE ATT&CK and security compliance standards including NIST, HIPAA, or SOC 2
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
  • Relevant certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User (highly preferred)

Technologies

  • Splunk SIEM
  • Splunk Enterprise Security
  • SPL (Splunk Processing Language)
  • Splunk correlation searches
  • MITRE ATT&CK
  • AWS, Azure, GCP
  • EDR
  • NIST, HIPAA, SOC 2

Similar Jobs