What are the responsibilities and job description for the Cybersecurity Engineer 3 - Must have local to Richmond, VA 23219 - Onsite position at HCL Global Systems Inc?
Responsibilities:
- Monitor network traffic, endpoint logs, and cloud security events for anomalous activity and potential security incidents.
- Use Splunk Enterprise Security to monitor, detect, analyze, and respond to security events.
- Create, maintain, and tune Splunk correlation searches, alerts, and dashboards.
- Develop and optimize SPL queries for security monitoring, threat detection, and investigation.
- Investigate potential security incidents and analyze forensic evidence.
- Conduct threat hunting to identify malicious activity and indicators of compromise.
- Collaborate with IT, network, infrastructure, and security teams to contain and remediate threats.
- Develop and refine security detection and response use cases.
- Create detection and response playbooks using threat intelligence and security frameworks such as MITRE ATT&CK.
- Work with infrastructure teams to onboard new log and security data sources.
- Ensure log integrity, parsing, and normalization across the SIEM platform.
- Support SIEM data integrations and troubleshooting.
- Collect SIEM control evidence for security audits.
- Generate compliance and security reports aligned with organizational policies and standards.
- Manage multiple security tickets and investigations while maintaining effective communication with stakeholders.
Requirements
Minimum Qualifications:
- 8 years of hands-on cybersecurity experience, specifically operating, building, and investigating threats within a SIEM or Splunk environment.
- 8 years of experience writing SPL (Splunk Processing Language).
- 8 years of experience demonstrating critical thinking, problem-solving, and communication skills.
- Ability to operate calmly under pressure and manage multiple security tickets.
- 8 years of experience with networking and firewalls.
- 8 years of experience with EDR technologies.
- 8 years of experience with cloud platforms, including AWS, Azure, and/or GCP.
- 8 years of experience with security frameworks such as MITRE ATT&CK.
- 8 years of experience with security compliance standards such as NIST, HIPAA, and/or SOC 2.
- Strong experience with log analysis, threat hunting, security monitoring, and incident investigation.
- Strong understanding of SIEM technologies and security event management.
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
Preferred Qualifications:
- Splunk Core Certified User certification.
- Splunk Core Certified Advanced Power User certification.
- Additional Splunk or cybersecurity certifications.
- Experience developing Splunk Enterprise Security dashboards, correlation searches, and alerts.
- Experience developing security detection and response playbooks.
- Experience applying threat intelligence and MITRE ATT&CK-based detection strategies.