IT Security SIEM Engineer (Splunk Experience is Required) - Hybrid Role in New York City
Booker DiMaio · New York, NY · 1 wk ago
Information TechnologyFull-time
Candidates must be within a commutable distance to New York City (10038). This is a 12-month contract to start, with a hybrid schedule requiring 3 days onsite and 2 days remote in New York City. Interviews will be conducted onsite.
About the role
We are seeking an IT Security SIEM Engineer with strong hands-on experience administering and engineering Splunk Enterprise and/or Splunk Cloud environments. This role combines SIEM engineering, security monitoring, scripting, automation, endpoint security, and incident response to help strengthen and support a large enterprise cybersecurity environment. Prior NYC government experience is highly preferred.
Responsibilities
- Engineer, administer, and support Splunk Enterprise and/or Splunk Cloud environments.
- Develop Splunk dashboards, reports, alerts, searches, and detection logic for security monitoring and operations.
- Onboard, normalize, and analyze logs from applications, databases, networks, cloud platforms, and endpoints.
- Investigate security events and support incident response, threat detection, and security monitoring activities.
- Develop automation scripts using PowerShell, Python, and/or Bash to improve operational efficiency.
- Support endpoint security, vulnerability remediation, patch validation, and security configuration management.
- Monitor infrastructure, network, and security logs while supporting compliance reporting, audits, and security documentation.
- Collaborate with security, infrastructure, and operations teams to improve enterprise cybersecurity capabilities.
Requirements
- Strong hands-on experience administering Splunk Enterprise and/or Splunk Cloud.
- Experience onboarding log sources and developing SIEM detection rules, dashboards, alerts, and reporting.
- Experience with enterprise logging across application, database, network, cloud, and endpoint environments.
- Experience with scripting and automation using PowerShell, Python, and/or Bash.
- Experience with endpoint detection and response (EDR) and endpoint security technologies.
- Knowledge of incident response, threat detection, log correlation, and security operations.
- Experience with IDS/IPS, host-based security tools, and enterprise security monitoring.
- Strong analytical and troubleshooting skills.
Preferred Qualifications
- Splunk Enterprise Certified Administrator or Architect
- CISSP
- CEH
- GCIH
- Security+
- Experience supporting enterprise cybersecurity or Security Operations Center (SOC) environments