NYC IT Inc
IT Security SIEM Engineer
Full Time • New York
Replies within 24 hours
We are seeking a Senior Splunk Security Engineer with 7+ years of experience supporting enterprise cybersecurity environments. The ideal candidate will have strong hands-on experience with Splunk Enterprise and/or Splunk Cloud, SIEM engineering, security operations, threat detection, scripting, automation, endpoint security, and incident response.
Key Responsibilities
- Administer and support Splunk Enterprise/Cloud environments, including Search Heads, Indexers, Deployers, Deployment Servers, Heavy/Universal Forwarders, and Splunk applications.
- Onboard and normalize application, database, network, cloud, and endpoint log sources.
- Develop and maintain Splunk dashboards, reports, alerts, searches, and threat detection use cases.
- Monitor security events, analyze logs, investigate incidents, and support SOC operations and incident response.
- Develop automation using PowerShell, Python, and Bash to improve operational efficiency, reporting, and security processes.
- Support endpoint security, including EDR, endpoint hardening, vulnerability remediation, patch validation, and compliance reporting.
- Monitor firewall and network security logs, support user access reviews, audits, security documentation, architecture diagrams, POAM tracking, and remediation validation.
Required Qualifications
- Strong 7+ years of experience with Splunk Enterprise and/or Splunk Cloud.
- Experience onboarding log sources and developing detection logic.
- Knowledge of enterprise logging, including application, web, database, security, and endpoint logs.
- Experience with PowerShell, Python, and Bash scripting.
- Experience with Endpoint Detection & Response (EDR) tools.
- Knowledge of incident response procedures.
- Understanding of log correlation and threat detection techniques.
- Experience with IDS/IPS and host-based security tools.
- Strong analytical, problem-solving, verbal, and written communication skills.
Preferred Certifications
- Splunk Enterprise Certified Admin or Architect.
- CISSP, CEH, GCIH, Security+, or equivalent cybersecurity certifications.
Work Schedule
- Business Hours: Monday – Friday, 9:00 AM – 5:00 PM
- Work Week: 35 hours per week, including a one-hour unpaid lunch break
- Work Arrangement: Hybrid (3 days onsite, 2 days remote). Applicants must reside in New York (NY) or New Jersey (NJ).
If you're passionate about cybersecurity and meet the qualifications above, we'd love to hear from you. Apply now!
Compensation: $75.00 - $85.00 per hour
(if you already have a resume on Indeed)