> Markdown version of [/jobs/ext/1204805-it-security-siem-engineer](https://www.wearedevelopers.com/jobs/ext/1204805-it-security-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security SIEM Engineer - **Company:** Oz Solutions Group Inc. - **Location:** New York, NY, United States (Remote available) - **Salary:** $62,400.0 - $83,200.0 - **Contract:** Temporary contract - **Skills:** Antivirus Softwares, Systems Engineering, Bash Shell, Cloud Computing, CompTIA Security+, Cyber Security, Databases, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Data Ingestion, Splunk - **Published:** July 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6d1ab0219cd03121 ## About the Role * Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud * Experience onboarding log sources and building detection logic * Knowledge of enterprise logging across application, web, database, security, and endpoint * Experience with scripting languages (PowerShell, Python, Bash) * Familiarity with endpoint detection and response (EDR) tools * Knowledge of incident response procedures * Understanding of log correlation and threat detection techniques * Experience with IDS/IPS and host-based security tools * Strong analytical and problem-solving skills * Ability to work independently and manage assigned tasks * Strong verbal and written communication skills Preferred Certifications: * Splunk Enterprise Certified Admin / Architect * CISSP, CEH, GCIH, Security+, or equivalent ## Description As an IT Security SIEM Engineer (Security Operations Consultant), you will support a highly visible cybersecurity program for a large-scale public sector organization, contributing across the full system engineering lifecycle - requirements analysis, design, development, implementation, integration, testing, and documentation. This role supports both strategic initiatives and day-to-day security operations in a hybrid environment, with a primary focus on SIEM engineering (Splunk), security monitoring, automation and scripting, endpoint protection, and overall operational security, working in coordination with the citywide Security Operations Center (SOC)., * Provide engineering and administration support for the organization's Splunk environment (cloud and/or hybrid), including search heads, indexers, deployers, deployment servers, and heavy/universal forwarders * Onboard and normalize new log sources across application, database, network, cloud, and endpoint * Develop and maintain complex Splunk queries, dashboards, reports, and alerts for both technical and executive audiences * Analyze log data for anomalies, suspicious trends, and potential security incidents; support log correlation and threat detection use cases aligned with SOC requirements * Tune alerts to reduce false positives and improve detection efficiency * Support day-to-day security monitoring, triage, and analysis of alerts and incidents in coordination with the SOC and internal teams * Support incident investigations using logs, endpoint data, and network telemetry, and contribute to incident response documentation and playbooks * Develop and maintain automation scripts (PowerShell, Python, Bash) to automate repetitive security tasks such as log ingestion validation, reporting, and compliance checks * Assist in monitoring and managing endpoint security tools (EDR, antivirus, host-based monitoring), endpoint hardening, and security configuration validation * Support vulnerability remediation coordination, patch validation, and compliance reporting * Review system and infrastructure logs, support firewall and network security log monitoring, and assist with user access reviews and audit support * Contribute to POAM tracking, remediation validation, and audit evidence preparation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)