- NYC IT Inc
- New York, NY
- Full-Time
- 68 days ago
IT Security SIEM Engineer.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
IT Security SIEM Engineer: our view in 3 lines...
- The Role:Senior Splunk Security Engineer role for someone with enterprise cybersecurity experience and strong SIEM engineering skills.
- The Person:The person will administer Splunk environments, onboard and normalize log sources, build dashboards and detections, investigate security events, and support endpoint security, audits, and remediation tracking.
- Requirements:The ideal candidate has 7+ years of experience with Splunk Enterprise and/or Splunk Cloud, PowerShell, Python, Bash, Endpoint Detection & Response tools, and incident response.
About the role
We are seeking a Senior Splunk Security Engineer with 7+ years of experience supporting enterprise cybersecurity environments. The ideal candidate will have strong hands-on experience with Splunk Enterprise and/or Splunk Cloud, SIEM engineering, security operations, threat detection, scripting, automation, endpoint security, and incident response.
Key Responsibilities
- Administer and support Splunk Enterprise/Cloud environments, including Search Heads, Indexers, Deployers, Deployment Servers, Heavy/Universal Forwarders, and Splunk applications.
- Onboard and normalize application, database, network, cloud, and endpoint log sources.
- Develop and maintain Splunk dashboards, reports, alerts, searches, and threat detection use cases.
- Monitor security events, analyze logs, investigate incidents, and support SOC operations and incident response.
- Develop automation using PowerShell, Python, and Bash to improve operational efficiency, reporting, and security processes.
- Support endpoint security, including EDR, endpoint hardening, vulnerability remediation, patch validation, and compliance reporting.
- Monitor firewall and network security logs, support user access reviews, audits, security documentation, architecture diagrams, POAM tracking, and remediation validation.
Required Qualifications
- Strong 7+ years of experience with Splunk Enterprise and/or Splunk Cloud.
- Experience onboarding log sources and developing detection logic.
- Knowledge of enterprise logging, including application, web, database, security, and endpoint logs.
- Experience with PowerShell, Python, and Bash scripting.
- Experience with Endpoint Detection & Response (EDR) tools.
- Knowledge of incident response procedures.
- Understanding of log correlation and threat detection techniques.
- Experience with IDS/IPS and host-based security tools.
- Strong analytical, problem-solving, verbal, and written communication skills.
Preferred Certifications
- Splunk Enterprise Certified Admin or Architect.
- CISSP, CEH, GCIH, Security+, or equivalent cybersecurity certifications.
Work Schedule
- Business Hours: Monday – Friday, 9:00 AM – 5:00 PM
- Work Week: 35 hours per week, including a one-hour unpaid lunch break
- Work Arrangement: Hybrid – 3 days onsite and 2 days remote
If you're passionate about cybersecurity and meet the qualifications above, we'd love to hear from you. Apply now!

