Job Description
Job Title: IT Security SIEM Engineer
Location: New York, NY
Duration: 12 Months
Work Schedule: Monday–Friday 9:00 AM – 5:00 PM 35 Hours/Week
Work Model: Hybrid (3 Days Onsite / 2 Days Remote)Job Summary
We are seeking an experienced IT Security SIEM Engineer to support enterprise cybersecurity operations by providing engineering, administration, and operational support across SIEM, endpoint security, automation, and security monitoring environments. The ideal candidate will have extensive hands-on experience with Splunk, security operations, incident response, scripting, and enterprise security technologies.Key ResponsibilitiesSIEM Engineering & Security Monitoring
Administer and support Splunk Enterprise and/or Splunk Cloud environments.
Configure and maintain Splunk infrastructure, including search heads, indexers, deployment servers, and forwarders.
Onboard and normalize application, database, cloud, network, and endpoint log sources.
Develop and maintain advanced Splunk searches, dashboards, reports, and alerts.
Analyze security logs to identify anomalies, suspicious activities, and potential threats.
Design dashboards and reporting solutions for technical and executive stakeholders.
Implement and optimize log correlation and threat detection use cases.
Fine-tune security alerts to reduce false positives and improve detection accuracy.
Collaborate with stakeholders to gather reporting and monitoring requirements.Security Operations & Incident Response
Support daily security monitoring activities.
Investigate security alerts and assist with incident triage and analysis.
Utilize logs, endpoint telemetry, and network data to support incident investigations.
Assist with containment, remediation, and recovery efforts during security incidents.
Develop and enhance detection rules, use cases, and incident response playbooks.Scripting & Automation
Develop automation scripts using PowerShell, Python, and Bash.
Automate security operations, reporting, compliance validation, and log ingestion tasks.
Build integrations between enterprise security tools.
Improve dashboard automation and scheduled reporting capabilities.Endpoint Security
Monitor and support enterprise endpoint security technologies, including EDR and antivirus platforms.
Assist with endpoint hardening and security configuration validation.
Coordinate vulnerability remediation activities.
Support security patch validation and compliance reporting.
Analyze endpoint telemetry to identify suspicious activity and recommend improvements.Operational IT Security
Review infrastructure and security logs.
Support firewall and network security monitoring activities.
Assist with user access reviews and security audits.
Maintain security documentation, architecture diagrams, and operational procedures.
Support remediation tracking and compliance reporting.
Prepare audit evidence and documentation for security assessments.Required Qualifications
Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
Experience onboarding enterprise log sources and developing detection logic.
Strong understanding of application, database, web, endpoint, and security logging.
Experience with PowerShell, Python, and Bash scripting.
Experience working with Endpoint Detection & Response (EDR) platforms.
Knowledge of enterprise incident response processes.
Understanding of SIEM correlation rules, threat detection, and security monitoring.
Experience with IDS/IPS and host-based security tools.
Strong analytical, troubleshooting, and problem-solving skills.
Excellent written and verbal communication skills.
Ability to work independently and effectively within cross-functional teams.Preferred Certifications
Splunk Enterprise Certified Administrator or Architect.
CISSP.
CEH (Certified Ethical Hacker).
GCIH (GIAC Certified Incident Handler).
CompTIA Security+ or equivalent cybersecurity certification.Preferred Skills
SIEM Engineering
Splunk Administration
Security Monitoring
Threat Detection
Incident Response
Endpoint Security
Log Analysis
Automation & Scripting
Vulnerability Management
Security Compliance
Network Security
Cloud Security
Full-time
Hybrid remote