Cybersecurity Engineer 3 (811203)

HCL Global Systems Inc.

  • Richmond, VA
  • 8 days ago

    Highlights

    Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents. • Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities.

    Numbers & Facts

    LocationRichmond, VA

    Description

    Key Responsibilities
    • Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents.
    • Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities.
    • Incident Response: Investigate potential security incidents, follow forensic evidence, and collaborate with IT and network teams to remediate threats.
    • Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and frameworks like MITRE Telecommunication&CK.
    • Log Integration: Work with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform.
    • Compliance & Reporting: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards

    Skill Required / Desired Amount of Experience
    Minimum of 8+ years of hands-on experience in cybersecurity, specifically operating, building, and investigating threats within a SIEM or Splunk. Required 8 Years
    Excellent critical thinking, problem-solving, and communication skills. Ability to operate calmly under pressure and manage multiple security tickets Required 8 Years
    Proficiency in writing SPL (Splunk Processing Language) Required 8 Years
    Strong understanding of networking, firewalls, EDR, and cloud platforms (AWS, Azure, or GCP). Required 8 Years
    Knowledge of security frameworks (e.g., MITRE Telecommunication&CK) and security compliance standards (e.g., NIST, HIPAA, or SOC 2). Required 8 Years
    Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field. Required
    Relevant certifications such as Splunk Core Certified User, Splunk Core Certified Advanced Power User, are highly preferred. Highly desired 8 Years

    Similar Jobs

    See more jobs