EngineerJobs.io
← Back to all jobs

Job Description

Cybersecurity Engineer role focused on building and operating advanced detection and response capabilities to protect enterprise infrastructure.

Responsibilities

  • Continuously review network traffic, endpoint logs, and cloud security events to identify anomalous activity and potential incidents
  • Build, maintain, and tune Splunk correlation searches, alerts, and dashboards to reduce false positives and strengthen detection
  • Investigate suspected security incidents using forensic evidence and coordinate with IT and network teams to remediate threats
  • Create and refine detection and response playbooks informed by threat intelligence and frameworks such as MITRE ATT&CK
  • Partner with infrastructure teams to onboard new data sources, ensuring log integrity plus correct parsing and normalization in the SIEM
  • Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned to internal policies and standards

Requirements

  • 8+ years of hands-on cybersecurity experience operating, building, and investigating threats within a SIEM, specifically Splunk (Splunk Enterprise Security)
  • Proven ability in critical thinking, problem-solving, and communication, including operating calmly under pressure and managing multiple security tickets
  • Proficiency writing SPL (Splunk Processing Language)
  • Strong working knowledge of networking, firewalls, EDR, and cloud platforms including AWS, Azure, or GCP
  • Knowledge of security frameworks and compliance standards such as MITRE ATT&CK, NIST, HIPAA, and SOC 2
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field

Technologies

  • Splunk SIEM and Splunk Enterprise Security
  • SPL (Splunk Processing Language)
  • Splunk correlation searches
  • MITRE ATT&CK
  • AWS, Azure, GCP
  • EDR
  • NIST, HIPAA, SOC 2

Location: Richmond, VA (onsite)

Similar Jobs