Cybersecurity Engineer 3
Core
Operate Splunk SIEM to monitor, detect, analyze, and respond to security events, investigate threats, and support secure system deployment for agency infrastructure.
Role type
Senior IC cybersecurity engineer (SIEM/Splunk)
Builds
Security detection and response use cases, playbooks, dashboards, and alerts
Domain
Public sector IT / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Splunk Enterprise Security, SPL (Splunk Processing Language), threat hunting, incident investigation, log analysis, network security, firewall management, EDR, cloud security (AWS/Azure/GCP), security frameworks (MITRE ATT&CK), compliance standards (NIST/HIPAA/SOC 2)
Preferred skills
Splunk Core Certified User, Splunk Core Certified Advanced Power User, security detection playbook development, threat intelligence integration
Technologies
Splunk, AWS, Azure, GCP, MITRE ATT&CK, NIST, HIPAA, SOC 2
Responsibilities
Monitor network traffic, endpoint logs, and cloud security events for anomalous activity; Create, maintain, and tune Splunk correlation searches, alerts, and dashboards; Develop and optimize SPL queries for security monitoring and threat detection; Investigate potential security incidents and analyze forensic evidence; Conduct threat hunting to identify malicious activity and indicators of compromise; Develop and refine security detection and response use cases; Create detection and response playbooks using threat intelligence and security frameworks; Work with infrastructure teams to onboard new log and security data sources; Ensure log integrity, parsing, and normalization across the SIEM platform; Collect SIEM control evidence for security audits; Generate compliance and security reports aligned with organizational policies and standards; Manage multiple security tickets and investigations
Seniority
Senior, hands-on IC