About The Position

We are seeking an IT Security SIEM Engineer with strong hands-on experience administering and engineering Splunk Enterprise and/or Splunk Cloud environments. This role combines SIEM engineering, security monitoring, scripting, automation, endpoint security, and incident response to help strengthen and support a large enterprise cybersecurity environment. The ideal candidate will have experience developing Splunk dashboards, onboarding log sources, building detection logic, and automating security operations using PowerShell, Python, or Bash. This is a hybrid position requiring 3 days onsite and 2 days remote in New York City.

Requirements

  • Strong hands-on experience administering Splunk Enterprise and/or Splunk Cloud.
  • Experience onboarding log sources and developing SIEM detection rules, dashboards, alerts, and reporting.
  • Experience with enterprise logging across application, database, network, cloud, and endpoint environments.
  • Experience with scripting and automation using PowerShell, Python, and/or Bash.
  • Experience with endpoint detection and response (EDR) and endpoint security technologies.
  • Knowledge of incident response, threat detection, log correlation, and security operations.
  • Experience with IDS/IPS, host-based security tools, and enterprise security monitoring.
  • Strong analytical and troubleshooting skills.

Nice To Haves

  • Splunk Enterprise Certified Administrator or Architect
  • CISSP
  • CEH
  • GCIH
  • Security+
  • Experience supporting enterprise cybersecurity or Security Operations Center (SOC) environments
  • Prior NYC government experience
  • Candidates must be within a commutable distance to New York City (10038)

Responsibilities

  • Engineer, administer, and support Splunk Enterprise and/or Splunk Cloud environments.
  • Develop Splunk dashboards, reports, alerts, searches, and detection logic for security monitoring and operations.
  • Onboard, normalize, and analyze logs from applications, databases, networks, cloud platforms, and endpoints.
  • Investigate security events and support incident response, threat detection, and security monitoring activities.
  • Develop automation scripts using PowerShell, Python, and/or Bash to improve operational efficiency.
  • Support endpoint security, vulnerability remediation, patch validation, and security configuration management.
  • Monitor infrastructure, network, and security logs while supporting compliance reporting, audits, and security documentation.
  • Collaborate with security, infrastructure, and operations teams to improve enterprise cybersecurity capabilities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service