Cybersecurity Engineer

Virginia Dept of Transportation
Richmond, VA, United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Data Integration Data Integrity Intrusion Detection and Prevention Network Security Log Analysis Network Monitoring Parsing
+10 more
Security Information and Event Management EndPointSecurity Google Cloud Mitre Att&ck Cyber Threat Analysis Firewalls (Computer Science) Information Technology Cybercrime Cyber Warfare Splunk

Job description

The Virginia Department of Transportation (VDOT) is seeking an experienced Cybersecurity Engineer 3 with strong expertise in Splunk SIEM to develop and implement advanced cyber defense solutions that protect enterprise infrastructure and critical systems. The ideal candidate will be responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while leveraging Splunk Enterprise Security for log analysis, threat hunting, incident response, and security monitoring., Monitor network traffic, endpoint logs, and cloud security events to detect suspicious activities and potential cyber threats. Develop, maintain, and optimize Splunk correlation searches, alerts, dashboards, and detection rules. Perform proactive threat hunting using Splunk Enterprise Security. Investigate security incidents and conduct forensic analysis to identify root causes. Collaborate with infrastructure, networking, and IT teams to contain and remediate security incidents. Develop and enhance security use cases, detection logic, and response playbooks based on MITRE ATT&CK and threat intelligence. Integrate new log sources into Splunk while ensuring proper parsing, normalization, and data integrity. Tune SIEM alerts to reduce false positives and improve threat detection accuracy. Generate compliance reports and provide SIEM evidence supporting internal and external audits. Support cybersecurity operations by managing multiple security incidents while maintaining high operational efficiency. Ensure enterprise cybersecurity solutions are built according to organizational security standards and deployed successfully.

Requirements

This role requires a highly analytical cybersecurity professional with extensive experience in SIEM operations, SPL query development, threat detection, incident investigation, log integration, and compliance reporting within enterprise environments., 8+ years of hands-on cybersecurity experience supporting enterprise SIEM platforms. Strong expertise with Splunk Enterprise Security (SIEM). Advanced experience writing SPL (Splunk Processing Language) queries. Experience building, managing, and investigating security threats using Splunk. Strong knowledge of: o Network Security o Firewalls o Endpoint Detection & Response (EDR) o Threat Hunting o Log Analysis o Incident Response Experience working with cloud platforms: o AWS o Microsoft Azure o Google Cloud Platform (Google Cloud Platform) Knowledge of cybersecurity frameworks: o MITRE ATT&CK o NIST o HIPAA o SOC 2 Experience with SIEM log onboarding, normalization, parsing, and data integration. Ability to create dashboards, alerts, correlation searches, and detection rules. Experience producing compliance reports and supporting audit readiness. Bachelor’s Degree in: o Computer Science o Cybersecurity o Information Technology o Or a related technical discipline., Splunk Core Certified User Splunk Core Certified Advanced Power User Experience with enterprise threat intelligence programs. Experience improving SIEM detection capabilities and reducing alert fatigue. Knowledge of enterprise cybersecurity architecture and security operations best practices. Experience supporting government or public sector environments is a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:36 min

Managing complex operation sequence weights using recursive parsing

Florian Rappl · LIVE

Videos

See all

Related articles

See all