You are viewing a preview of this job. Log in or register to view more details about this job.

Position:  SIEM Security Engineer (Ref: 18784)

Location:  Harrisburg, PA USA, 17120

Salary:  DOE

Duration:  8 Months 20 Days - Contract

Openings:  1

Deadline:  10/15/2026

Description:

***Local Candidates

***Hybrid – onsite 3 days/week

 

We are seeking an experienced SIEM Security Engineer to provide specialized, hands-on engineering support for an enterprise Security Information and Event Management (SIEM) environment. In this role, you will support the design, configuration, integration, optimization, and ongoing operation of the SIEM platform to strengthen enterprise security monitoring, threat detection, incident response, and log management capabilities. 

 

Key Responsibilities

  • Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
  • Onboard new data sources, ensuring logs are properly collected, parsed, normalized, indexed, and retained.
  • Develop, tune, and maintain correlation searches, alerts, dashboards, reports, and detection rules to improve security monitoring effectiveness and reduce false positives.
  • Integrate SIEM capabilities with third-party security tools, cloud platforms, enterprise infrastructure, and business applications.
  • Continuously monitor SIEM platform health, performance, capacity, and availability while troubleshooting technical issues.
  • Support Security Operations Center (SOC) analysts and Incident Response (IR) personnel by building targeted queries, custom dashboards, and investigative workflows.
  • Execute platform upgrades, patch management, configuration changes, and infrastructure testing in accordance with change-management protocols.
  • Create and maintain comprehensive operational procedures, system configuration documentation, and knowledge-transfer materials.
  • Collaborate cross-functionally with SOC, infrastructure, cloud, networking, and application teams to execute security initiatives.
  • Ensure all engineering practices align strictly with established organizational cybersecurity standards and regulatory compliance policies.

 

Requirements & Qualifications

  • Proven hands-on experience in enterprise-level SIEM engineering, architecture, and administration (specifically with Splunk).
  • Demonstrated expertise in log onboarding, custom parsing, field extraction, data normalization, and retention lifecycle management.
  • Strong background developing complex correlation searches, detection logic, and custom dashboards.
  • Practical experience integrating SIEM environments across hybrid enterprise infrastructures, including multi-cloud environments and modern security toolings.
  • Solid understanding of SOC operations, incident handling frameworks, and threat detection workflows.
  • Ability to work effectively in a hybrid setup requiring onsite presence in Harrisburg, PA three days per week.
  • Ability to participate in an in-person interview.
  • Must be able to pass an enhanced background check.

 

Work Arrangement: 

  • Hybrid (3 days onsite per week in Harrisburg, PA)
  • Position Type: Contract (37.5 hours/week)

 

Required / Desired Skills

  • Professional IT experience including at least three years supporting SIEM, security engineering, cybersecurity operations, or security monitoring tech Required - 3 Years
  • Experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security. Required - 3 Years
  • Demonstrated experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integration Required - 3 Years
  • Certifications: Splunk Enterprise Certified Admin Required - 1 Years
  • Experience supporting a large enterprise or government environment. Required - 1 Years
  • Experience developing SPL searches, dashboards, alerts, correlation searches, and reports. Required - 1 Years
  • Experience troubleshooting complex SIEM, logging, data ingestion, or integration issues. Required - 1 Years
  • Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK. Required - 1 Years