Cybersecurity Engineer - Richmond
Salary: $60,000 - 100,000 per year
Requirements:
We require at least 8 years of hands-on cybersecurity experience supporting enterprise SIEM platforms. We need strong expertise in Splunk Enterprise Security and advanced proficiency writing SPL queries. We expect experience building, managing, and investigating security threats using Splunk. We are looking for solid knowledge of network security, firewalls, endpoint detection and response, threat hunting, log analysis, and incident response. We require experience working with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform. We expect familiarity with cybersecurity frameworks and standards including MITRE ATT&CK, NIST, HIPAA, and SOC 2. We need experience with SIEM log onboarding, normalization, parsing, and data integration. We require the ability to create dashboards, alerts, correlation searches, and detection rules. We expect experience producing compliance reports and supporting audit readiness. We require a bachelors degree in Computer Science, Cybersecurity, Information Technology, or a related technical field. Preferred: Splunk Core Certified User or Splunk Core Certified Advanced Power User. Preferred: Experience with enterprise threat intelligence programs. Preferred: Experience improving SIEM detections and reducing alert fatigue. Preferred: Knowledge of enterprise cybersecurity architecture and security operations best practices. Preferred: Experience supporting government or public sector environments.
Responsibilities:
We monitor network traffic, endpoint logs, and cloud security events to identify suspicious behavior and emerging threats. We develop, maintain, and refine Splunk correlation searches, alerts, dashboards, and detection logic. We perform proactive threat hunting using Splunk Enterprise Security. We investigate security incidents and carry out forensic analysis to determine root causes. We collaborate with infrastructure, networking, and IT teams to contain and remediate incidents. We design and enhance security use cases, detection logic, and response playbooks aligned to MITRE ATT&CK and threat intelligence. We onboard new log sources into Splunk and ensure proper parsing, normalization, and data integrity. We tune SIEM alerts to reduce false positives and improve detection accuracy. We produce compliance reports and provide SIEM evidence to support internal and external audits. We support cybersecurity operations by managing multiple incidents efficiently. We ensure enterprise cybersecurity solutions meet organizational security standards and are deployed successfully.
Technologies:
AWS Azure Cloud Support Network Security Splunk
More:
We are Virginia Department of Transportation (VDOT) and we are hiring a Cybersecurity Engineer 3 for a long-term contract based in Richmond, VA. In this role, we focus on strengthening enterprise defenses for critical systems through advanced Splunk SIEM operations, threat detection, incident response, and compliance support. This position offers the opportunity to work across infrastructure, networking, IT, and security teams in a high-impact public sector environment.
last updated 31 week of 2026