Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
CI

SIEM Security Engineer (Splunk)

Crescens Inc.
  • πŸ‡ΊπŸ‡Έ United States
  • Hybrid
  • Mid level
  • 10 hours ago
  • SIEM
  • Splunk
  • Incident Response
  • Change Management
  • NIST
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Job Title: SIEM Security Engineer (Splunk)
Location: Harrisburg, PA (Hybrid – 3 Days Onsite per Week)
Duration: 6+ Months
Type: Contract

Interview:
In-person interview required.

Job Description

We are seeking an experienced SIEM Security Engineer to provide specialized engineering support for the Commonwealth of Pennsylvania's Security Information and Event Management (SIEM) environment. The ideal candidate will have strong hands-on experience with Splunk Enterprise and/or Splunk Enterprise Security, cybersecurity operations, security monitoring, and log management.

The candidate will support the design, configuration, integration, optimization, and ongoing operation of the SIEM platform to strengthen enterprise security monitoring, threat detection, incident response, and log management capabilities. This role involves working closely with SOC analysts, infrastructure, cloud, networking, and application teams to maintain effective security monitoring and detection capabilities.

Key Responsibilities

  • Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
  • Onboard new data sources and ensure logs are properly collected, parsed, normalized, indexed, and retained.
  • Develop and maintain SPL searches, correlation searches, alerts, dashboards, reports, and detection rules.
  • Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and other enterprise systems.
  • Monitor SIEM platform performance, capacity, availability, and overall health, and troubleshoot technical issues.
  • Tune alerts and detection logic to reduce false positives and improve security monitoring effectiveness.
  • Provide technical support to SOC analysts and incident response personnel through queries, dashboards, and investigative capabilities.
  • Support upgrades, patches, configuration changes, testing, and implementation of supporting SIEM infrastructure.
  • Develop and maintain technical documentation, operational procedures, system configurations, and knowledge-transfer materials.
  • Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.
  • Follow Commonwealth security standards, change-management processes, and applicable cybersecurity policies and requirements.

Required Qualifications

  • Minimum of 3 years of professional IT experience supporting SIEM, security engineering, cybersecurity operations, or security monitoring technologies.
  • Minimum of 3 years of experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security.
  • Minimum of 3 years of experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integrations.

Preferred Qualifications

  • Splunk Enterprise Certified Admin certification.
  • Experience supporting large enterprise or government environments.
  • Experience developing SPL searches, dashboards, alerts, correlation searches, and reports.
  • Experience troubleshooting complex SIEM, logging, data ingestion, and integration issues.
  • Familiarity with cybersecurity frameworks such as NIST and MITRE Telecommunication&CK.

SIEM Security Engineer (Splunk) Β· Crescens Inc.

Auto apply with Likeremote