SIEM Engineer (Splunk/ Secret)

Insight Global

Fulton (MD)

Hybrid

USD 120,000 - 180,000

Full time

11 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Benefits from Day 1

Job summary

Insight Global is seeking a proactive SIEM Engineer focused on Splunk engineering, detection development, and cloud security operations. The role supports security monitoring and incident response across Splunk ES, Splunk SOAR, and cloud platforms in AWS and Azure environments.

The ideal candidate will develop detections, dashboards, automation workflows, and data onboarding initiatives, while troubleshooting and maintaining distributed Splunk environments.

Qualifications

  • 5+ years of professional experience in SIEM engineering, security operations, or incident response.
  • Ability to write complex SPL queries and build dashboards in Splunk.
  • Experience onboarding/integrating security data sources into Splunk and integrating tools like AWS Security Hub.
  • Willingness to participate in on-call rotation.
  • Proven ability to present technical findings to diverse stakeholders.

Responsibilities

  • Develop and optimize Splunk ES detections, dashboards, and correlation searches.
  • Support Splunk SOAR playbook development and automation workflows.
  • Onboard, parse, normalize, and enrich security data sources into Splunk.
  • Troubleshoot ingestion pipelines, forwarder connectivity, and search performance.
  • Collaborate with SOC analysts and engineering to improve visibility and detection coverage.
  • Participate in on-call rotations and 24/7 incident response activities.

Skills

SIEM engineering
Splunk SPL queries
Data onboarding into Splunk
Incident response
Communication

Tools

Splunk Enterprise
Splunk Enterprise Security (ES)
Splunk SOAR

Job description

12 mo. w-2 contract, yearly renewing with benefits available from Day 1.

Fulton, MD, hybrid 2 days onsite per week. This role is also available in Raleigh, NC.

Required Skills & Experience
  • Experience: Minimum of 5 years of professional experience in a SIEM Engineering, Security Operations or Incident Response environment.
  • Splunk Proficiency: Demonstrated ability to write complex SPL queries, build/maintain production-grade dashboards, and perform data normalization within Splunk Enterprise or Splunk Enterprise Security (ES).
  • Experience onboarding and integrating security data sources into Splunk. Experience integrating security tools (e.g., AWS Security Hub) into a centralized SIEM. Understanding of Splunk knowledge objects, field extractions, lookups, and CIM normalization.
  • Operational Mindset: Ability to handle high-pressure incident response scenarios and a willingness to participate in an on-call rotation.
  • Communication: Proven ability to present technical findings and dashboard insights to both technical and non-technical stakeholders.
Nice to Have Skills & Experience
  • Splunk Enterprise Security (ES) Certified Admin and/or Splunk Core Certified Power User.
  • Certifications such as GCIH, GCIA, or Azure/AWS Security certifications.
  • Experience in a multi-cloud environment (AWS/Azure) specifically focusing on identity and access management (Entra ID).
Job Description

We are seeking a proactive SIEM Engineer with a strong focus on Splunk engineering, detection development, and cloud security operations. This role will support the organization’s security monitoring and incident response capabilities by leveraging Splunk Enterprise Security (ES), Splunk SOAR, and integrated cloud/security platforms across AWS and Azure environments.

The ideal candidate will contribute to the development and optimization of detections, dashboards, automation workflows, and data onboarding initiatives while assisting with troubleshooting and maintaining distributed Splunk environments. This individual will work closely with SOC analysts, cloud teams, and engineering stakeholders to improve security visibility, operational efficiency, and threat detection capabilities.

This position requires a blend of security operations experience and hands‑on Splunk engineering skills, including data normalization, ingestion troubleshooting, search optimization, and security analytics development. The candidate should be comfortable operating in a fast‑paced 24/7 security environment, participating in on‑call rotations, and supporting continuous improvement initiatives across the security operations program.

Role Responsibilities
  • Develop, maintain, and optimize Splunk Enterprise Security (ES) detections, dashboards, and correlation searches
  • Support Splunk SOAR playbook development and automation workflows
  • Assist with onboarding, parsing, normalization, and enrichment of security data sources into Splunk
  • Troubleshoot Splunk ingestion pipelines, forwarder connectivity, search performance, and indexing issues
  • Create and maintain knowledge objects including field extractions, lookups, event types, tags, and macros client Confidential
  • Assist with Splunk configuration changes and troubleshooting across distributed Splunk environments
  • Leverage data models and accelerated searches to improve detection and reporting performance
  • Collaborate with SOC analysts and engineering teams to improve visibility, detection coverage, and operational efficiency
Incident Response & Operations
  • Incident response efforts, conducting deep‑Dive investigations into alerts generated by our security stack.
  • Coordinate with internal teams to contain and remediate threats.
  • Participate in a scheduled on‑call rotation to ensure 24/7 incident coverage and rapid response.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.

To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000
SIEM Engineer - Secret Cleared
SIEM Engineer - Secret Cleared

Piper Companies • Fulton (MD), Raleigh (NC)

Hybrid
USD 115,000 - 125,000
Medical benefits
Dental benefits
Vision benefits
+2
Sr. Splunk / SIEM Engineer (TS Required)
Sr. Splunk / SIEM Engineer (TS Required)

augustschell • Alexandria (VA)

Hybrid
USD 100,000 - 130,000
Cybersecurity Engineer 4 - SIEM / Splunk Engineer
Cybersecurity Engineer 4 - SIEM / Splunk Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
SIEM(Security Information & Event Management) Engineer
SIEM(Security Information & Event Management) Engineer

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
Security Information Event Manager (SIEM) Administrator
Security Information Event Manager (SIEM) Administrator

Castalia Systems • Waipahu (HI)

On-site
USD 120,000 - 124,000
Security Information Event Manager (SIEM) Administrator
Security Information Event Manager (SIEM) Administrator

castaliasystems • Waipahu (HI)

On-site
USD 120,000 - 124,000