Cybersecurity Engineer Splunk SIEM Threat Detection

Rose International

Richmond (VA)

On-site

USD 90,000 - 96,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Rose International (Richmond, VA) is seeking a Cybersecurity Engineer specialized in Splunk SIEM to join our onsite, temporary team for a 10-month assignment.

The role focuses on threat detection, log analysis, and incident response, leveraging Splunk Enterprise Security to monitor and respond to security events. The ideal candidate has 8+ years in security operations and strong communication under pressure.

Qualifications

  • Hands-on cybersecurity experience with SIEM/Splunk threat detection.
  • Strong problem-solving and communication skills under pressure.
  • Proficiency in SPL (Splunk Processing Language): 8+ years.
  • Knowledge of networking, firewalls, EDR, and cloud platforms (AWS/Azure/GCP): 8+ years.
  • Knowledge of MITRE ATT&CK and NIST/HIPAA/SOC 2 security standards: 8+ years.

Responsibilities

  • Threat Detection & Monitoring: monitor network traffic, logs, and cloud events.
  • Splunk Management: tune searches, alerts, dashboards to minimize false positives.
  • Incident Response: investigate incidents and remediate threats.
  • Use Case Development: develop detection/playbooks based on MITRE ATT&CK.
  • Log Integration: onboard data sources and normalize logs across the SIEM.
  • Compliance & Reporting: assist audit readiness with SIEM evidence and reports.

Skills

Cybersecurity
Firewall
HIPAA
Networking

Education

Bachelor's Degree

Tools

Splunk

Job description

Date Posted

09/21/2026

Hiring Organization

Rose International

Position Number

507856

Industry

Government/Staffing

Job Title

Cybersecurity Engineer Splunk SIEM Threat Detection

Job Location

Richmond, VA, USA, 23219

Work Model

Onsite

Shift

Regular

Employment Type

Temporary

FT/PT

Full-Time

Estimated Duration (In months)

10

Min Hourly Rate($)

65.00

Max Hourly Rate($)

70.00

Must Have Skills/Attributes

Cybersecurity, Firewall, HIPAA, Networking

Experience Desired

Knowledge of security frameworks (e.g., MITRE ATT&CK) and security compliance standards (e.g., NIST) (8 yrs); Strong understanding of networking, firewalls, EDR, and cloud platforms (AWS, Azure, or GCP) (8 yrs); Proficiency in writing SPL (Splunk Processing Language) (8 yrs); Excellent critical thinking, problem-solving, and communication skills. Ability to operate calmly (8 yrs); Cybersecurity, specifically operating, building, and investigating threats within a SIEM or Splunk (8 yrs)

Required Minimum Education

Bachelor’s Degree

Preferred Certifications/Licenses

Certifications such as Splunk Core Certified User, Splunk Core Certified Advanced Power User

C2C is not available

Job Description

REQUIRED EDUCATION:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
Preferred Certification
  • Relevant certifications such as Splunk Core Certified User, Splunk Core Certified Advanced Power User, are highly preferred
Required Skills/ Experience
  • Hands-on experience in cybersecurity, specifically operating, building, and investigating threats within a SIEM or Splunk: 8 Years
  • Excellent critical thinking, problem-solving, and communication skills. Ability to operate calmly under pressure and manage multiple security tickets: 8 Years
  • Proficiency in writing SPL (Splunk Processing Language): 8 Years
  • Strong understanding of networking, firewalls, EDR, and cloud platforms (AWS, Azure, or GCP): 8 Years
  • Knowledge of security frameworks (e.g., MITRE ATT&CK) and security compliance standards (e.g., NIST, HIPAA, or SOC 2): 8 Years
ABOUT THE ROLE:

The Cybersecurity Engineer develops and implements advanced cyber defense solutions for the agency, safeguards the infrastructure, and assures that the system is built to specification and is deployed successfully. We are seeking a highly analytical and technically proficient Cybersecurity Engineer supporting Splunk SIEM. You will play a critical role in defending our organization against cyber threats by leveraging Splunk Enterprise Security to monitor, detect, analyze, and respond to security events. The ideal candidate has strong expertise in log analysis, threat hunting, and writing Splunk queries to identify and contain malicious activity.

Responsibilities
  • Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents
  • Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities
  • Incident Response: Investigate potential security incidents, follow forensic evidence, and collaborate with IT and network teams to remediate threats
  • Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and frameworks like MITRE ATT&CK
  • Log Integration: Work with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform
  • Compliance & Reporting: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards
  • Only those lawfully authorized to work in the designated country associated with the position will be considered.
  • Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.
Benefits

Should you have any questions/concerns, please contact our HR Department via our secure website.

Rose International is an Equal Opportunity Employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

Assistance for applicants with disabilities

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Agreement with Government

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Analyst Cybersecurity NIST SIEM
Network Security Analyst Cybersecurity NIST SIEM

Rose International • Columbia (SC)

On-site
USD 76,000 - 80,000
Cybersecurity Engineer 3 – Contract Position
Cybersecurity Engineer 3 – Contract Position

BranCore Technologies • Richmond (VA)

On-site
USD 110,000 - 165,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates, Inc • Richmond (VA)

On-site
USD 110,000 - 150,000
Must be Virginia Locals || Cybersecurity Engineer || 1099/W2 Role
Must be Virginia Locals || Cybersecurity Engineer || 1099/W2 Role

VLS Systems Inc • Richmond (VA)

On-site
USD 120,000 - 180,000
Splunk Detection Engineer
Splunk Detection Engineer

Boston Government Services • Los Alamos (NM)

On-site
USD 120,000 - 180,000
Health Insurance
401K
Paid Vacation
+4
Cybersecurity Engineer
Cybersecurity Engineer

Global Sumi Technologies Inc., • Richmond (VA)

On-site
USD 110,000 - 170,000
Splunk Cyber Security SME
Splunk Cyber Security SME

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 160,000
Cybersecurity Engineer 3 - Hybrid Richmond, VA
Cybersecurity Engineer 3 - Hybrid Richmond, VA

Novalink Solutions LLC • Richmond (VA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

DataStaff, Inc. • Richmond (VA)

On-site
USD 110,000 - 150,000
Medical insurance
Dental coverage
Vision coverage
+2
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000