IT Security SIEM Engineer (Splunk Experience...
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
-
Engineer, administer, and support Splunk Enterprise and/or Splunk Cloud environments.
-
Develop Splunk dashboards, reports, alerts, searches, and detection logic for security monitoring and operations.
-
Onboard, normalize, and analyze logs from applications, databases, networks, cloud platforms, and endpoints.
-
Investigate security events and support incident response, threat detection, and security monitoring activities.
-
Develop automation scripts using PowerShell, Python, and/or Bash to improve operational efficiency.
-
Support endpoint security, vulnerability remediation, patch validation, and security configuration management.
-
Monitor infrastructure, network, and security logs while supporting compliance reporting, audits, and security documentation.
-
Collaborate with security, infrastructure, and operations teams to improve enterprise cybersecurity capabilities.
Requirements
Strong Splunk experience is mandatory.
Prior NYC government is highly preferred., We are seeking an IT Security SIEM Engineer with strong hands-on experience administering and engineering Splunk Enterprise and/or Splunk Cloud environments. This role combines SIEM engineering, security monitoring, scripting, automation, endpoint security, and incident response to help strengthen and support a large enterprise cybersecurity environment. The ideal candidate will have experience developing Splunk dashboards, onboarding log sources, building detection logic, and automating security operations using PowerShell, Python, or Bash. This is a hybrid position requiring 3 days onsite and 2 days remote in New York City., + Strong hands-on experience administering Splunk Enterprise and/or Splunk Cloud.
-
Experience onboarding log sources and developing SIEM detection rules, dashboards, alerts, and reporting.
-
Experience with enterprise logging across application, database, network, cloud, and endpoint environments.
-
Experience with scripting and automation using PowerShell, Python, and/or Bash.
-
Experience with endpoint detection and response (EDR) and endpoint security technologies.
-
Knowledge of incident response, threat detection, log correlation, and security operations.
-
Experience with IDS/IPS, host-based security tools, and enterprise security monitoring.
-
Strong analytical and troubleshooting skills.
Preferred Qualifications
-
Splunk Enterprise Certified Administrator or Architect
-
CISSP
-
CEH
-
GCIH
-
Security
-
- Experience supporting enterprise cybersecurity or Security Operations Center (SOC) environments
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.juju.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Software Engineer Salary London
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology
Is Software Engineering Over-Saturated?