Job Requirements
Fulton, MD
Secret Polygraph Unspecified
Career Level not specified
$110,000 - $130,000
Job Description
Piper Companies is looking to fill the role of for a Cloud and Technology company located in Morrisville, NC. The will support the organization's security monitoring and incident response capabilities by leveraging Splunk Enterprise Security (ES), Splunk SOAR, and integrated cloud/security platforms across AWS and Azure environments.
This job opens for applications on 7/29/2026. Applications for this job will be accepted for at least 30 days from the posting date.
Keywords: SOC, SOC engineer II, Security, Secret clearance, Cloud Security, Tier II
#LI-EB1 #HYBRID
- Developed and optimized Splunk Enterprise Security (ES) detections, correlation searches, dashboards, and reporting to enhance threat visibility and detection coverage.
- Supported Splunk SOAR playbook development, security automation initiatives, and the onboarding, normalization, and enrichment of security data sources.
- Troubleshot data ingestion pipelines, forwarder connectivity, search performance, indexing issues, and configuration changes across distributed Splunk environments.
- Created and maintained Splunk knowledge objects, including field extractions, lookups, event types, tags, macros, and accelerated data models.
- Conducted incident response investigations, analyzing security alerts and coordinating with cross-functional teams to contain, remediate, and document security incidents.
- Collaborated with SOC analysts and engineering teams while participating in a 24/7 on-call rotation to improve operational efficiency and ensure timely response to security events.
- 5+ years of experience in SIEM engineering, SOC operations, incident response, or cybersecurity engineering, with the ability to perform effectively in high-pressure environments and participate in an on-call rotation, and active secret clearance.
- Strong Splunk Enterprise and Splunk Enterprise Security (ES) expertise, including advanced SPL development, dashboard creation, analytics, detections, reporting, data normalization, and use case development.
- Experience onboarding, parsing, and integrating security data sources and tools into a centralized SIEM, including AWS Security Hub, AWS Config, and other enterprise security platforms.
- Solid understanding of Splunk knowledge objects, field extractions, lookups, CIM normalization, data models, and dashboard optimization in distributed Splunk environments.
- Experience supporting Tier 2 SOC operations, investigating security incidents, presenting technical findings to technical and non-technical stakeholders, and collaborating with cross-functional teams.
- Preferred qualifications include Splunk ES Certified Admin and/or Splunk Core Power User, Security+ or equivalent, GCIH/GCIA/AWS/Azure security certifications, and experience in AWS/Azure environments with Entra ID.
- $110,000-$130,000
- Contract
- Benefits: Medical, Dental, Vision, 401k, PTO, Sick leave if required by law, and Holidays
This job opens for applications on 7/29/2026. Applications for this job will be accepted for at least 30 days from the posting date.
Keywords: SOC, SOC engineer II, Security, Secret clearance, Cloud Security, Tier II
#LI-EB1 #HYBRID
group id: 10430981