Cybersecurity Engineer (Ref: 18559)
Position: Cybersecurity Engineer (Ref: 18559)
Location: Richmond, VA USA, 23219
Salary: DOE
Duration: 10 Months 27 Days - Contract
Openings: 1
Deadline: 08/07/2026
Description:
***Work Arrangement: Onsite
***Location: Richmond, VA
We are seeking a highly analytical and technically proficient Cybersecurity Engineer with a strong focus on Splunk SIEM. In this role, you will play a critical part in defending our enterprise environment against cyber threats by leveraging Splunk Enterprise Security to monitor, detect, analyze, and respond to security events.
The ideal candidate will possess deep expertise in log analysis, threat hunting, and authoring complex Splunk queries to identify and mitigate malicious activity across enterprise systems.
Key Responsibilities
• Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents.
• Splunk SIEM Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and enhance threat detection capabilities.
• Incident Response & Investigation: Investigate potential security incidents, follow forensic evidence, and collaborate closely with IT and network engineering teams to remediate threats.
• Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and industry frameworks such as MITRE ATT&CK.
• Log Onboarding & Integration: Collaborate with infrastructure teams to find onboard new data sources, ensuring proper log integrity, parsing, and normalization across the SIEM platform.
• Compliance & Audit Support: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal security policies and standards.
Preferred Qualifications & Experience
• Hands-on experience engineering and managing Splunk Enterprise / Splunk Enterprise Security (ES) environments.
• Strong knowledge of SIEM log ingestion, parsing rules, and data normalization techniques.
• Experience in threat hunting, log analysis, and developing customs Splunk Search Processing Language (SPL) queries.
• Familiarity with network protocols, cloud environments, endpoint detection tools, and security event logs.
• Solid understanding of framework-driven detection strategies (e.g., MITRE ATT&CK).
• Ability to work effectively onsite and collaborate with technical IT and network operations teams.
Required / Desired Skills
• Experience in cybersecurity, specifically operating, building, and investigating threats within a SIEM or Splunk. Required - 8 Years
• Excellent critical thinking, problem-solving, and communication skills. Ability to operate calmly under pressure and manage multiple security tickets Required - 8 Years
• Proficiency in writing SPL (Splunk Processing Language) Required - 8 Years
• Strong understanding of networking, firewalls, EDR, and cloud platforms (AWS, Azure, or GCP). Required - 8 Years
• Knowledge of security frameworks (e.g., MITRE ATT&CK) and security compliance standards (e.g., NIST, HIPAA, or SOC 2). Required - 8 Years
• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. Required - 4 Years
• Relevant certifications such as Splunk Core Certified User, Splunk Core Certified Advanced Power User, are highly preferred. Required - 8 Years