IT Security SIEM Engineer - 26-09172

CVC - IT

Philadelphia, PA

JOB DETAILS
SKILLS
Administrative Skills, Analysis Skills, Antivirus, Automation, Bash Scripting, CEH - Certified Ethical Hacker, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, CompTIA Security+, Computer Security, Cross-Functional, Documentation, Endpoint Security, Enterprise Endpoint, Enterprise Protection, Environmental Monitoring, Firewalls, Forwarder, GCIH - GIAC Certified Incident Handler, Identify Issues, Incident Management, Incident Response, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Network Monitoring, Network Security, Network Support, Onboarding, Operational Support, Operations Processes, Operations Security (OPSEC), Presentation/Verbal Skills, Problem Solving Skills, Python Programming/Scripting Language, Reporting Dashboards, Reporting Skills, Scripting (Scripting Languages), Security Analysis, Security Architecture, Security Auditing, Security Compliance, Security Information and Event Management (SIEM), Security Monitoring, Security Patches, Splunk, Telemetry, Use Cases, Windows PowerShell, Writing Skills
LOCATION
Philadelphia, PA
POSTED
1 day ago

Job Title: IT Security SIEM Engineer

Location: New York, NY
Duration: 12 Months
Work Schedule: Monday–Friday | 9:00 AM – 5:00 PM | 35 Hours/Week
Work Model: Hybrid (3 Days Onsite / 2 Days Remote)

Job Summary

We are seeking an experienced IT Security SIEM Engineer to support enterprise cybersecurity operations by providing engineering, administration, and operational support across SIEM, endpoint security, automation, and security monitoring environments. The ideal candidate will have extensive hands-on experience with Splunk, security operations, incident response, scripting, and enterprise security technologies.

Key Responsibilities

SIEM Engineering & Security Monitoring

  • Administer and support Splunk Enterprise and/or Splunk Cloud environments.
  • Configure and maintain Splunk infrastructure, including search heads, indexers, deployment servers, and forwarders.
  • Onboard and normalize application, database, cloud, network, and endpoint log sources.
  • Develop and maintain advanced Splunk searches, dashboards, reports, and alerts.
  • Analyze security logs to identify anomalies, suspicious activities, and potential threats.
  • Design dashboards and reporting solutions for technical and executive stakeholders.
  • Implement and optimize log correlation and threat detection use cases.
  • Fine-tune security alerts to reduce false positives and improve detection accuracy.
  • Collaborate with stakeholders to gather reporting and monitoring requirements.

Security Operations & Incident Response

  • Support daily security monitoring activities.
  • Investigate security alerts and assist with incident triage and analysis.
  • Utilize logs, endpoint telemetry, and network data to support incident investigations.
  • Assist with containment, remediation, and recovery efforts during security incidents.
  • Develop and enhance detection rules, use cases, and incident response playbooks.

Scripting & Automation

  • Develop automation scripts using PowerShell, Python, and Bash.
  • Automate security operations, reporting, compliance validation, and log ingestion tasks.
  • Build integrations between enterprise security tools.
  • Improve dashboard automation and scheduled reporting capabilities.

Endpoint Security

  • Monitor and support enterprise endpoint security technologies, including EDR and antivirus platforms.
  • Assist with endpoint hardening and security configuration validation.
  • Coordinate vulnerability remediation activities.
  • Support security patch validation and compliance reporting.
  • Analyze endpoint telemetry to identify suspicious activity and recommend improvements.

Operational IT Security

  • Review infrastructure and security logs.
  • Support firewall and network security monitoring activities.
  • Assist with user access reviews and security audits.
  • Maintain security documentation, architecture diagrams, and operational procedures.
  • Support remediation tracking and compliance reporting.
  • Prepare audit evidence and documentation for security assessments.

Required Qualifications

  • Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
  • Experience onboarding enterprise log sources and developing detection logic.
  • Strong understanding of application, database, web, endpoint, and security logging.
  • Experience with PowerShell, Python, and Bash scripting.
  • Experience working with Endpoint Detection & Response (EDR) platforms.
  • Knowledge of enterprise incident response processes.
  • Understanding of SIEM correlation rules, threat detection, and security monitoring.
  • Experience with IDS/IPS and host-based security tools.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently and effectively within cross-functional teams.

Preferred Certifications

  • Splunk Enterprise Certified Administrator or Architect.
  • CISSP.
  • CEH (Certified Ethical Hacker).
  • GCIH (GIAC Certified Incident Handler).
  • CompTIA Security+ or equivalent cybersecurity certification.

Preferred Skills

  • SIEM Engineering
  • Splunk Administration
  • Security Monitoring
  • Threat Detection
  • Incident Response
  • Endpoint Security
  • Log Analysis
  • Automation & Scripting
  • Vulnerability Management
  • Security Compliance
  • Network Security
  • Cloud Security

About the Company

C

CVC - IT