Sr Security Engineer with SPLUNK/SIEM
Job Description
CTC Group, Inc. is seeking a Sr Security Engineer with SPLUNK/SIEM to support an enterprise SIEM program in a hands-on, technical capacity. This contract role is based in Harrisburg, PA with a hybrid work setup, focusing on Splunk platform operations, detection engineering, and log management to support security monitoring and incident response.
You will work closely with security monitoring teams by designing, configuring, and optimizing the SIEM environment, ensuring the platform remains healthy and available while enabling high-quality data ingestion and detection content. The position also includes investigative support for SOC analysts through custom queries, dashboards, and technical guidance.
Key Responsibilities
- Engineer, configure, maintain, and optimize the enterprise SIEM platform including Splunk and related security tools.
- Execute upgrades, patches, testing, and system changes while maintaining platform health, capacity, and availability.
- Onboard new data sources by parsing, normalizing, indexing, and managing log retention using syslog, APIs, forwarders/agents, and cloud integrations.
- Build and maintain correlation searches, custom alerts, dashboards, reports, and detection rules for security monitoring content.
- Fine-tune detection logic and alerts to reduce false positives, and resolve complex SIEM, data ingestion, and integration issues.
- Integrate SIEM capabilities with security infrastructure, cloud platforms, networks, and enterprise applications.
- Provide technical expertise, custom Search Processing Language (SPL) queries, investigative dashboards, and support to SOC analysts and incident response teams.
- Maintain system configurations, operational procedures, and technical documentation, following change-management workflows, security standards, and policy compliance requirements.
Required Qualifications
- Minimum 3 years of professional IT experience in SIEM, security engineering, SOC operations, or security monitoring technologies.
- Minimum 3 years administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
- Minimum 3 years onboarding and integrating log sources using syslog, APIs, forwarders/agents, or cloud-native integrations.
- Splunk Enterprise Certified Admin (Required).
Technologies
- Splunk, Splunk Enterprise, Splunk Enterprise Security
- SIEM
- Search Processing Language (SPL)
- syslog, APIs
- forwarders/agents, cloud integrations, cloud-native integrations
- NIST CSF, MITRE ATT&CK
Highly Desired Qualifications
- Experience engineering SIEM solutions within large enterprise or government environments.
- Strong proficiency developing complex SPL queries, dashboards, alerts, and correlation searches.
- Hands-on troubleshooting of complex logging pipelines and data ingestion failures.
- Familiarity with cybersecurity frameworks including NIST CSF and MITRE ATT&CK.
Location: Harrisburg, PA (hybrid)
Compensation: USD 120-130 per hour
Experience: minimum 3 years
Job Type: contract