Cybersecurity Engineer - Richmond, VA

QTechRichmond, VA
Onsite

About The Position

The Virginia Department of Transportation (VDOT) is seeking an experienced Cybersecurity Engineer 3 with strong expertise in Splunk SIEM to develop and implement advanced cyber defense solutions that protect enterprise infrastructure and critical systems. The ideal candidate will be responsible for monitoring, detecting, investigating, and responding to cybersecurity threats while leveraging Splunk Enterprise Security for log analysis, threat hunting, incident response, and security monitoring. This role requires a highly analytical cybersecurity professional with extensive experience in SIEM operations, SPL query development, threat detection, incident investigation, log integration, and compliance reporting within enterprise environments.

Requirements

  • 8+ years of hands-on cybersecurity experience supporting enterprise SIEM platforms.
  • Strong expertise with Splunk Enterprise Security (SIEM).
  • Advanced experience writing SPL (Splunk Processing Language) queries.
  • Experience building, managing, and investigating security threats using Splunk.
  • Strong knowledge of Network Security
  • Strong knowledge of Firewalls
  • Strong knowledge of Endpoint Detection & Response (EDR)
  • Strong knowledge of Threat Hunting
  • Strong knowledge of Log Analysis
  • Strong knowledge of Incident Response
  • Experience working with cloud platforms: AWS
  • Experience working with cloud platforms: Microsoft Azure
  • Experience working with cloud platforms: Google Cloud Platform (GCP)
  • Knowledge of cybersecurity frameworks: MITRE ATT&CK
  • Knowledge of cybersecurity frameworks: NIST
  • Knowledge of cybersecurity frameworks: HIPAA
  • Knowledge of cybersecurity frameworks: SOC 2
  • Experience with SIEM log onboarding, normalization, parsing, and data integration.
  • Ability to create dashboards, alerts, correlation searches, and detection rules.
  • Experience producing compliance reports and supporting audit readiness.
  • Bachelor's Degree in Computer Science
  • Bachelor's Degree in Cybersecurity
  • Bachelor's Degree in Information Technology
  • Bachelor's Degree in a related technical discipline.

Nice To Haves

  • Splunk Core Certified User
  • Splunk Core Certified Advanced Power User
  • Experience with enterprise threat intelligence programs.
  • Experience improving SIEM detection capabilities and reducing alert fatigue.
  • Knowledge of enterprise cybersecurity architecture and security operations best practices.
  • Experience supporting government or public sector environments is a plus.

Responsibilities

  • Monitor network traffic, endpoint logs, and cloud security events to detect suspicious activities and potential cyber threats.
  • Develop, maintain, and optimize Splunk correlation searches, alerts, dashboards, and detection rules.
  • Perform proactive threat hunting using Splunk Enterprise Security.
  • Investigate security incidents and conduct forensic analysis to identify root causes.
  • Collaborate with infrastructure, networking, and IT teams to contain and remediate security incidents.
  • Develop and enhance security use cases, detection logic, and response playbooks based on MITRE ATT&CK and threat intelligence.
  • Integrate new log sources into Splunk while ensuring proper parsing, normalization, and data integrity.
  • Tune SIEM alerts to reduce false positives and improve threat detection accuracy.
  • Generate compliance reports and provide SIEM evidence supporting internal and external audits.
  • Support cybersecurity operations by managing multiple security incidents while maintaining high operational efficiency.
  • Ensure enterprise cybersecurity solutions are built according to organizational security standards and deployed successfully.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service