Cybersecurity Engineer
Cloud Platforms
Cloud Security
Cyber Forensics
Cybersecurity Tools
Detection Engineering
Endpoint Security
Incident Response
Information Security
Investigative Skills
Log Management
Security
Security Compliance
Security Information And Event Management
Security Operations
Security Standards
Siem
Splunk
Splunk Enterprise Security
Job Description
The Cybersecurity Engineer role at Skywalk Global is focused on supporting a Splunk SIEM program to monitor, detect, analyze, and respond to security events. This position emphasizes building high-fidelity Splunk detections, conducting incident investigations, and translating threat intelligence into structured detection and response playbooks.
Location
Richmond, VA (onsite)
Role Summary
As a Cybersecurity Engineer, you will operate and improve Splunk SIEM capabilities by creating and tuning detections, investigating potential security incidents, and developing detection playbooks grounded in threat intelligence and frameworks such as MITRE ATT&CK.
Responsibilities
- Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential incidents.
- Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to reduce false positives and strengthen detection effectiveness.
- Investigate potential security incidents, follow forensic evidence, and partner with IT and network teams to remediate threats.
- Develop and refine detection and response playbooks using threat intelligence and frameworks such as MITRE ATT&CK.
- Coordinate with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform.
- Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards.
Required Qualifications
- Minimum 8+ years of hands-on cybersecurity experience, operating, building, and investigating threats within a SIEM or Splunk.
- Excellent critical thinking, problem-solving, and communication skills, with the ability to stay composed under pressure and manage multiple security tickets.
- Proficiency in writing SPL (Splunk Processing Language).
- Strong understanding of networking, firewalls, EDR, and cloud platforms including AWS, Azure, or GCP.
- Knowledge of security frameworks (e.g., MITRE ATT&CK) and security compliance standards (e.g., NIST, HIPAA, or SOC 2).
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
Preferred Qualifications
- Relevant certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User.
Technologies
- Splunk SIEM
- Splunk Enterprise Security
- SPL (Splunk Processing Language)
- Splunk correlation searches
- MITRE ATT&CK
- AWS, Azure, GCP
- EDR
- NIST, HIPAA, SOC 2