IT Security SIEM Engineer

NYC IT IncNew York, NY
$75 - $85Hybrid

About The Position

We are seeking a Senior Splunk Security Engineer with 7+ years of experience supporting enterprise cybersecurity environments. The ideal candidate will have strong hands-on experience with Splunk Enterprise and/or Splunk Cloud, SIEM engineering, security operations, threat detection, scripting, automation, endpoint security, and incident response.

Requirements

  • Strong 7+ years of experience with Splunk Enterprise and/or Splunk Cloud.
  • Experience onboarding log sources and developing detection logic.
  • Knowledge of enterprise logging, including application, web, database, security, and endpoint logs.
  • Experience with PowerShell, Python, and Bash scripting.
  • Experience with Endpoint Detection & Response (EDR) tools.
  • Knowledge of incident response procedures.
  • Understanding of log correlation and threat detection techniques.
  • Experience with IDS/IPS and host-based security tools.
  • Strong analytical, problem-solving, verbal, and written communication skills.

Nice To Haves

  • Splunk Enterprise Certified Admin or Architect.
  • CISSP, CEH, GCIH, Security+, or equivalent cybersecurity certifications.

Responsibilities

  • Administer and support Splunk Enterprise/Cloud environments, including Search Heads, Indexers, Deployers, Deployment Servers, Heavy/Universal Forwarders, and Splunk applications.
  • Onboard and normalize application, database, network, cloud, and endpoint log sources.
  • Develop and maintain Splunk dashboards, reports, alerts, searches, and threat detection use cases.
  • Monitor security events, analyze logs, investigate incidents, and support SOC operations and incident response.
  • Develop automation using PowerShell, Python, and Bash to improve operational efficiency, reporting, and security processes.
  • Support endpoint security, including EDR, endpoint hardening, vulnerability remediation, patch validation, and compliance reporting.
  • Monitor firewall and network security logs, support user access reviews, audits, security documentation, architecture diagrams, POAM tracking, and remediation validation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service