IT Security SIEM Engineer (Splunk Experience is Required) - Hybrid Role in New York City

New York, NY
Contracted
CV-NYC-SIEM/Splunk-NYC
Mid Level
Strong Splunk experience is mandatory.

Prior NYC government is highly preferred.

Candidates must be within a commutable distance to New York City (10038)

This job is onsite in NYC 3 days/week and remote the other 2 days


Interviews will be onsite

This is a 12-month contract to start

We are seeking an IT Security SIEM Engineer with strong hands-on experience administering and engineering Splunk Enterprise and/or Splunk Cloud environments. This role combines SIEM engineering, security monitoring, scripting, automation, endpoint security, and incident response to help strengthen and support a large enterprise cybersecurity environment. The ideal candidate will have experience developing Splunk dashboards, onboarding log sources, building detection logic, and automating security operations using PowerShell, Python, or Bash. This is a hybrid position requiring 3 days onsite and 2 days remote in New York City.

Key Responsibilities
  • Engineer, administer, and support Splunk Enterprise and/or Splunk Cloud environments.
  • Develop Splunk dashboards, reports, alerts, searches, and detection logic for security monitoring and operations.
  • Onboard, normalize, and analyze logs from applications, databases, networks, cloud platforms, and endpoints.
  • Investigate security events and support incident response, threat detection, and security monitoring activities.
  • Develop automation scripts using PowerShell, Python, and/or Bash to improve operational efficiency.
  • Support endpoint security, vulnerability remediation, patch validation, and security configuration management.
  • Monitor infrastructure, network, and security logs while supporting compliance reporting, audits, and security documentation.
  • Collaborate with security, infrastructure, and operations teams to improve enterprise cybersecurity capabilities.

Required Qualifications
  • Strong hands-on experience administering Splunk Enterprise and/or Splunk Cloud.
  • Experience onboarding log sources and developing SIEM detection rules, dashboards, alerts, and reporting.
  • Experience with enterprise logging across application, database, network, cloud, and endpoint environments.
  • Experience with scripting and automation using PowerShell, Python, and/or Bash.
  • Experience with endpoint detection and response (EDR) and endpoint security technologies.
  • Knowledge of incident response, threat detection, log correlation, and security operations.
  • Experience with IDS/IPS, host-based security tools, and enterprise security monitoring.
  • Strong analytical and troubleshooting skills.

Preferred Qualifications
  • Splunk Enterprise Certified Administrator or Architect
  • CISSP
  • CEH
  • GCIH
  • Security+
  • Experience supporting enterprise cybersecurity or Security Operations Center (SOC) environments
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*