A

Cybersecurity Engineer 4 - SIEM / SPLUNK Engineer

Posted today

Job Requirements

Columbus, OH Richmond, VA
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

The Cybersecurity Engineers will support a Federal cybersecurity technology program responsible for securing enterprise infrastructure and mission systems within a large federal operational environment. The Cybersecurity Engineer 4 will support enterprise Security Information and Event Management (SIEM) and log management systems. This role focuses on administration, engineering, and enhancement of Splunk Enterprise Security environments used for threat detection, security monitoring, and incident response.

Key Responsibilities
- Administer and maintain Splunk Enterprise Security (ES) and enterprise log management systems.
- Design and implement custom dashboards, alerts, correlation rules, and threat detection use cases.
- Analyze threat data collected from security logs, IDS systems, intelligence feeds, and other sources.
- Develop monitoring dashboards to support incident response and threat detection operations.
- Perform installation, configuration, and lifecycle maintenance of the Splunk ELM architecture.
- Optimize data ingestion, indexing performance, and storage management within the Splunk environment.
- Support system upgrades, maintenance, and troubleshooting of Splunk infrastructure.
- Develop reports, rules, and automated monitoring workflows to enhance threat detection. Collaborate with incident response teams and security analysts to support enterprise cybersecurity operations.

Required Qualifications
- 7+ years of relevant IT / cybersecurity experience
- Active DoD Secret Clearance
- Must meet DoD 8570 / 8140 IAT Level III certification requirements - candidate must possess one of the following certifications: CASP+ CE, CCNP Security, CISA, CISSP, GCED, GCIH, CCSP
- Must meet DoD 8570 / 8140 CND-IS certification requirements - candidate must possess one of the following certifications: CEH, GICSP, GCIH, GCIA, CFR
- Must be eligible for IT Level I access
- Computing Environment Certification: Linux+ certification
- Computing Environment Certification: Splunk Administrator certification
- Experience developing custom Splunk dashboards and reports
- Experience supporting Splunk Core and Splunk Enterprise Security (ES)

Preferred Skills
- Experience supporting enterprise SIEM architectures
- Experience with threat hunting and security analytics
- Familiarity with large-scale log ingestion and correlation systems
group id: 10280020