About this role
Hello,
Role: SIEM Engineer
Location: Keystone Building, 5th Floor, Harrisburg, PA 17120
Client : Commonwealth of Pennsylvania
Hybrid – 3 days onsite per week
Interview Type: In-person
Visa: All visa accepted apart from EAD/OPT's. (C2C Accepted).
J ob Description:
The Commonwealth of Pennsylvania is seeking an experienced SIEM Engineer to provide specialized engineering support for its enterprise Security Information and Event Management (SIEM) environment. The consultant will be responsible for designing, configuring, integrating, optimizing, and maintaining SIEM capabilities to strengthen security monitoring, threat detection, incident response, and log management.
This is a hands-on technical role reporting to the Director. Strategic direction, governance, and overall program oversight will remain with the Director.
Key Responsibilities:
- Engineer, configure, maintain, and optimize the enterprise SIEM platform, including Splunk and related security technologies.
- Onboard new data sources and ensure proper log collection, parsing, normalization, indexing, and retention.
- Develop and maintain correlation searches, alerts, dashboards, reports, detection rules, and security monitoring content.
- Integrate SIEM capabilities with security tools, cloud platforms, applications, infrastructure, and enterprise systems.
- Monitor platform performance, capacity, availability, and overall health; troubleshoot technical issues as needed.
- Tune alerts and detection logic to reduce false positives and improve threat detection effectiveness.
- Provide technical support to SOC analysts and incident response teams, including queries, dashboards, and investigative capabilities.
- Support upgrades, patches, configuration changes, testing, and SIEM infrastructure implementation.
- Maintain technical documentation, operational procedures, system configurations, and knowledge-transfer materials.
- Collaborate with SOC, infrastructure, cloud, networking, and application teams on SIEM initiatives.
- Follow Commonwealth security standards, change-management processes, and applicable cybersecurity policies.
Ideal Candidate Profile
- Strong hands-on experience with Splunk and enterprise SIEM engineering.
- Experience with log ingestion, parsing, normalization, indexing, and retention.
- Proficiency in developing correlation searches, detection rules, alerts, dashboards, and reports.
- Experience integrating SIEM platforms with cloud, infrastructure, application, and security technologies.
- Strong troubleshooting, performance optimization, and alert-tuning skills.
- Experience supporting SOC operations, threat detection, and incident response.
- Excellent technical documentation and cross-functional collaboration skills.