MSys Inc. logo

Senior Splunk/SIEM Engineer - Hybrid - In Person Interview

MSys Inc.

Harrisburg, PA · HybridContractSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Harrisburg, PAHybrid
Schedule
Contract
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Senior Splunk/SIEM Engineer provides hands-on engineering support for the Commonwealth’s SIEM environment, reporting to the Director. The role supports design, configuration, integration, optimization, and operation of the platform to strengthen security monitoring, threat detection, incident response, and log management. Strategic direction, governance, and program oversight remain with the Director. The position is hybrid, with three days per week onsite.

Skills & qualifications

RequiredNice to have

Skills

SIEM EngineeringCybersecurity OperationsSecurity MonitoringSplunk EnterpriseSplunk Enterprise SecuritySecurity Log IntegrationSyslogAPIsAgentsCloud-Native IntegrationSplunk Enterprise AdministrationSPLDashboard DevelopmentAlert DevelopmentCorrelation SearchesReport DevelopmentSIEM TroubleshootingLog Ingestion TroubleshootingNISTMITRE ATT&CK

Qualifications

3 Years SIEM or Security Experience3 Years Splunk Experience3 Years Security Log IntegrationSplunk Enterprise Certified AdminLarge Enterprise or Government Experience

Full job description

*** In Person Interview*** Long term contract Hybrid*(3 Days Per Week Onsite)

Job Description

Provide specialized engineering support for the Commonwealth's Security Information and Event Management (SIEM) environment. The contractor will support the design, configuration, integration, optimization, and ongoing operation of the SIEM platform to strengthen enterprise security monitoring, threat detection, incident response, and log management capabilities. This position reports to the Director and provides hands-on technical support for the SIEM environment. Strategic direction, governance, and overall program oversight remain with the Director.

Duties

  • Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.

  • Onboard new data sources and ensure logs are properly collected, parsed, normalized, indexed, and retained.

  • Develop and maintain correlation searches, alerts, dashboards, reports, detection rules, and other security monitoring content.

  • Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and other enterprise systems.

  • Monitor SIEM platform performance, capacity, availability, and overall health and troubleshoot technical issues.

  • Tune alerts and detection logic to reduce false positives and improve the effectiveness of security monitoring.

  • Support SOC analysts and incident response personnel by providing technical expertise, queries, dashboards, and investigative capabilities.

  • Support upgrades, patches, configuration changes, testing, and implementation of supporting SIEM infrastructure.

  • Develop and maintain technical documentation operational procedures, system configurations, and knowledge-transfer materials.

  • Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM-related initiatives.

  • Follow Commonwealth security standards, change-management processes, and applicable cybersecurity policies and requirements.

Skills/Requirements

Skill Required Years

Professional IT experience including at least three years supporting SIEM, security engineering, cybersecurity operations, or security monitoring tech Required 3 Years

Experience administering or engineering Splunk Enterprise and/or Splunk Enterprise Security. Required 3 Years

Demonstrated experience onboarding and integrating security log sources using technologies such as syslog, APIs, agents, or cloud-native integration Required 3 Years

Certifications: Splunk Enterprise Certified Admin Highly desired

Experience supporting a large enterprise or government environment. Highly desired

Experience developing SPL searches, dashboards, alerts, correlation searches, and reports. Highly desired

Experience troubleshooting complex SIEM, logging, data ingestion, or integration issues. Highly desired

Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK. Highly desired

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.