STN
USA Jobs Board

IT Security SIEM Engineer (Splunk Experience is Required) - Hybrid Role in New York City

Booker DiMaio, LLC · New York, NY
Category Engineering
Type CONTRACTOR
Posted 4d ago
View and Apply

Opens the original job posting in a new tab.

Job description

Strong Splunk experience is mandatory. Prior NYC government is highly preferred. Candidates must be within a commutable distance to New York City (10038) This job is onsite in NYC 3 days/week and remote the other 2 days Interviews will be onsite This is a 12-month contract to start We are seeking an  IT Security SIEM Engineer  with strong hands-on experience administering and engineering  Splunk Enterprise and/or Splunk Cloud  environments.

This role combines SIEM engineering, security monitoring, scripting, automation, endpoint security, and incident response to help strengthen and support a large enterprise cybersecurity environment. The ideal candidate will have experience developing Splunk dashboards, onboarding log sources, building detection logic, and automating security operations using PowerShell, Python, or Bash. This is a hybrid position requiring  3 days onsite and 2 days remote  in New York City.

Key Responsibilities

  • Engineer, administer, and support Splunk Enterprise and/or Splunk Cloud environments.
  • Develop Splunk dashboards, reports, alerts, searches, and detection logic for security monitoring and operations.
  • Onboard, normalize, and analyze logs from applications, databases, networks, cloud platforms, and endpoints.
  • Investigate security events and support incident response, threat detection, and security monitoring activities.
  • Develop automation scripts using PowerShell, Python, and/or Bash to improve operational efficiency.
  • Support endpoint security, vulnerability remediation, patch validation, and security configuration management.
  • Monitor infrastructure, network, and security logs while supporting compliance reporting, audits, and security documentation.
  • Collaborate with security, infrastructure, and operations teams to improve enterprise cybersecurity capabilities.

Required Qualifications

  • Strong hands-on experience administering  Splunk Enterprise  and/or  Splunk Cloud .
  • Experience onboarding log sources and developing SIEM detection rules, dashboards, alerts, and reporting.
  • Experience with enterprise logging across application, database, network, cloud, and endpoint environments.
  • Experience with scripting and automation using  PowerShell, Python, and/or Bash .
  • Experience with endpoint detection and response (EDR) and endpoint security technologies.
  • Knowledge of incident response, threat detection, log correlation, and security operations.
  • Experience with IDS/IPS, host-based security tools, and enterprise security monitoring.
  • Strong analytical and troubleshooting skills.

Preferred Qualifications

  • Splunk Enterprise Certified Administrator or Architect
  • CISSP
  • CEH
  • GCIH
  • Security+
  • Experience supporting enterprise cybersecurity or Security Operations Center (SOC) environments