HT
SIEM Consultant (Splunk)
HonorVet Technologies
- 🇺🇸 United States
- Hybrid
- Mid level
- 9 hours ago
- $90 – $95 / hour
- ISO 27001
- SIEM
- Splunk
- Incident Response
- Change Management
- NIST
9 hours ago
Job Title: SIEM Consultant (Splunk)
Duration: 2+ Months
Location: Harrisburg, PA
Work Environment: Hybrid – Onsite 3 Days/Week
Working Hours: 7.5 Hours/Day
Interview Mode: In-Person Only
Job Summary
Seeking an experienced SIEM Consultant to provide hands-on engineering support for an enterprise SIEM environment, focusing on Splunk administration, security monitoring, threat detection, incident response, and log management.
Key Responsibilities
- Engineer, configure, maintain, and optimize Splunk and related SIEM technologies.
- Onboard and integrate security log sources, ensuring proper collection, parsing, normalization, indexing, and retention.
- Develop and maintain SPL searches, correlation searches, alerts, dashboards, reports, and detection rules.
- Integrate SIEM with security tools, cloud platforms, applications, infrastructure, and enterprise systems.
- Monitor platform performance, capacity, availability, and health; troubleshoot SIEM, logging, ingestion, and integration issues.
- Tune alerts and detection logic to reduce false positives and improve threat detection.
- Support SOC analysts and incident response teams with queries, dashboards, and investigations.
- Support upgrades, patches, configuration changes, testing, and SIEM infrastructure implementation.
- Maintain technical documentation, operational procedures, system configurations, and knowledge-transfer materials.
- Collaborate with security, infrastructure, cloud, networking, and application teams while following security standards and change-management policies.
Required Qualifications
- Minimum 3 years of professional IT experience in SIEM, security engineering, cybersecurity operations, or security monitoring.
- Minimum 3 years of experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
- Minimum 3 years of experience onboarding and integrating security log sources using syslog, APIs, agents, or cloud-native integrations.
Preferred Qualifications
- Splunk Enterprise Certified Admin certification.
- Experience in large enterprise or government environments.
- Proficiency in SPL searches, dashboards, alerts, correlation searches, and reports.
- Strong troubleshooting experience with SIEM, logging, data ingestion, and integrations.
- Familiarity with NIST and MITRE ATT&CK cybersecurity frameworks.
If you are interested, feel free to reach out to me directly at paula.scott@honorvettech.com
SIEM Consultant (Splunk) · HonorVet Technologies