CareerPlanGet AI match score →

Cybersecurity Engineer 3

Richmond, Virginia, United States💼 Full-time🗓 2026-08-01

Job Title: Cybersecurity Engineer 3
Work Type: Onsite
Location: Richmond, VA 23219
Start Date: 08/31/2026
End Date: 06/30/2027
Industry Category: Information Technology / Government
Employment Type: 1099 Contract
Requisition ID: 807541

Overview

We are seeking an experienced Cybersecurity Engineer to strengthen the agency's cybersecurity operations by developing and implementing advanced cyber defense solutions. This role is responsible for safeguarding enterprise infrastructure, supporting Splunk SIEM operations, detecting and responding to cyber threats, and ensuring security solutions are implemented according to agency standards. The ideal candidate is a highly analytical security professional with deep experience in SIEM operations, threat detection, incident response, and security monitoring.

Application

Applications will be reviewed as received.

Candidates must:

• Meet all required qualifications.
• Be available to interview in person.
• Physically reside within the United States for the duration of the assignment.
• Be legally authorized to work in the United States without employer sponsorship, now or in the future.

Job Description

The Cybersecurity Engineer will support VDOT's cybersecurity operations by leveraging Splunk Enterprise Security to monitor, detect, investigate, and respond to cybersecurity threats across enterprise environments. This position works closely with infrastructure, networking, and IT teams to improve detection capabilities, onboard new log sources, develop threat detection use cases, and support security compliance initiatives while protecting critical systems and data.

Responsibilities

Threat Detection & Monitoring

• Continuously monitor network traffic, endpoint activity, cloud environments, and security logs for suspicious behavior and potential security incidents.
• Perform proactive threat hunting using Splunk Enterprise Security and advanced analytical techniques.
• Identify, analyze, and prioritize security events requiring investigation.

Splunk SIEM Administration

• Create, maintain, optimize, and tune Splunk correlation searches, dashboards, alerts, and detection rules.
• Develop efficient SPL (Splunk Processing Language) queries to improve threat detection and reduce false positives.
• Support onboarding, parsing, normalization, and validation of new log sources within the SIEM platform.

Incident Response

• Investigate security incidents and analyze forensic evidence to determine root cause and impact.
• Collaborate with infrastructure, networking, and IT teams to contain, remediate, and recover from cybersecurity events.
• Document findings and contribute to continuous improvement of incident response procedures.

Security Engineering & Threat Intelligence

• Develop and enhance detection use cases and response playbooks using threat intelligence and security frameworks such as MITRE ATT&CK.
• Support implementation of advanced cyber defense capabilities that strengthen enterprise security posture.
• Recommend improvements to monitoring, detection, and response processes.

Compliance & Reporting

• Generate security reports and SIEM metrics supporting audit readiness.
• Collect and maintain evidence required for security and compliance reviews.
• Support compliance efforts aligned with recognized security standards and internal policies.

Minimum Qualifications

• Minimum of 8 years of hands-on cybersecurity experience operating, building, and investigating threats within SIEM or Splunk environments.
• Minimum of 8 years of experience writing and optimizing SPL (Splunk Processing Language).
• Minimum of 8 years of experience with networking concepts, firewalls, endpoint detection and response (EDR), and cloud platforms such as AWS, Azure, or GCP.
• Minimum of 8 years of experience applying security frameworks and compliance standards such as MITRE ATT&CK, NIST, HIPAA, or SOC 2.
• Minimum of 8 years demonstrating excellent critical thinking, problem-solving, communication, and the ability to manage multiple security incidents under pressure.
• Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
• Must physically reside within the United States for the duration of the assignment.
• Must attend an in-person interview.
• Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Preferred Qualifications

• Minimum of 8 years of experience supported by Splunk certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User.

Compensation

This is a 1099 Contract opportunity.

Pay Rate: $62 – $82 per hour

Schedule

• Assignment Start Date: 08/31/2026
• Assignment End Date: 06/30/2027
• Assignment Duration: Approximately 10 months
• Work Arrangement: Onsite

Work Location

• Richmond, VA
• This position requires full-time onsite attendance.

Sourced via workable · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Workable ↗