CybersecurityJobs.io
← Back to all jobs

Job Description

The Cybersecurity Engineer will develop and implement advanced cyber defense capabilities while operating and enhancing a Splunk SIEM environment. This onsite role in Richmond, VA supports Splunk Enterprise Security for monitoring, detection, analysis, and response to security events, with emphasis on log analysis, threat hunting, incident response, and Splunk detection and compliance reporting.

Key Responsibilities

  • Continuously monitor network traffic, endpoint logs, and cloud security events to identify anomalous behavior and potential security incidents.
  • Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to reduce false positives and strengthen detection coverage.
  • Investigate potential security incidents, follow forensic evidence, and coordinate with IT and network teams to remediate identified threats.
  • Develop and refine detection and response playbooks using threat intelligence and frameworks such as MITRE ATT&CK.
  • Partner with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization within the SIEM platform.
  • Support audit readiness by collecting SIEM control evidence and producing compliance reports aligned with internal policies and standards.

Required Qualifications

  • 8+ years of hands-on cybersecurity experience, specifically operating, building, and investigating threats within a SIEM or Splunk environment.
  • Excellent critical thinking, problem-solving, and communication skills, including the ability to manage multiple security tickets and operate calmly under pressure.
  • Proficiency writing SPL (Splunk Processing Language).
  • Strong understanding of networking, firewalls, EDR, and cloud platforms such as AWS, Azure, or GCP.
  • Knowledge of security frameworks (for example, MITRE ATT&CK) and security compliance standards such as NIST, HIPAA, or SOC 2.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Relevant certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User are highly preferred.

Technologies and Tools

  • Splunk SIEM
  • Splunk Enterprise Security
  • Splunk Processing Language (SPL)
  • MITRE ATT&CK
  • AWS, Azure, GCP
  • NIST, HIPAA, SOC 2
  • EDR

Benefits

  • Long-Term Stability: Multi-year opportunities with room to grow.
  • Comprehensive Health Coverage: Healthcare benefits for you and your family.
  • 401(k) Program: Retirement savings with future planning support.
  • GC Assistance: Support for immediate Green Card processing, if required.

Education

Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.

Similar Jobs