1

Splunk Cybersecurity Defense Analyst Jobs in Raleigh, NC

SIEM Engineer

Raleigh, NC · On-site

$105 - $120/hr

... in the cybersecurity and defense industry in the RTP area. The SIEM Engineer role is a hybrid ... The SIEM Engineer is best suited for a security professional with strong Splunk expertise, AWS ...

... and defense operations. This role provides frontline IT support in a highly regulated, mission ... Follow cybersecurity best practices and company security policies. * Escalate complex issues to ...

Cyber Insider Risk Manager

Raleigh, NC · On-site

$107K - $145K/yr

Cyber Defense & Resilience - Senior Consultant Are you interested in working in a dynamic ... the triage, analysis, investigation, and remediation of insider risk-related inquiries Leading ...

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by ... Work you'll do As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be ...

... analysis, documentation, reporting, or workflow automation, with awareness of risks such as data ... Splunk Cloud Platform, Enterprise Security, SOAR, or Observability Cloud. Cybersecurity, cloud, or ...

... analysis, documentation, reporting, or workflow automation, with awareness of risks such as data ... Splunk Cloud Platform, Enterprise Security, SOAR, or Observability Cloud. • Cybersecurity, cloud ...

Showing results 41-60

Splunk Cybersecurity Defense Analyst information

See Raleigh, NC salary details

$41.8K

$96.6K

$145.8K

How much do splunk cybersecurity defense analyst jobs pay per year?

As of Sep 7, 2026, the average yearly pay for splunk cybersecurity defense analyst in Raleigh, NC is $96,625.00, according to ZipRecruiter salary data. Most workers in this role earn between $77,300.00 and $112,300.00 per year, depending on experience, location, and employer.

What is a Splunk Cybersecurity Defense Analyst?

Splunk Cybersecurity Defense Analysts are professionals who use the Splunk platform to monitor, analyze, and defend an organization’s digital infrastructure against cyber threats. They collect and interpret security data, investigate incidents, and create alerts and dashboards to detect suspicious activity in real-time. Their work helps organizations respond quickly to threats, ensuring the safety and integrity of sensitive information and systems. These analysts often collaborate with IT and security teams to develop best practices for threat detection and response.

How does a Splunk Cybersecurity Defense Analyst typically collaborate with other IT and security teams?

A Splunk Cybersecurity Defense Analyst frequently works alongside network administrators, incident response teams, and other security professionals to detect, investigate, and remediate threats. Collaboration often involves sharing threat intelligence, creating automated alerts, and developing dashboards to provide visibility into security events across the organization. Analysts also participate in regular meetings to coordinate response strategies, review incident post-mortems, and ensure that Splunk configurations align with evolving security requirements. This cross-functional teamwork is essential for maintaining an effective and proactive cybersecurity posture.

What are the key skills and qualifications needed to thrive as a Splunk Cybersecurity Defense Analyst, and why are they important?

To thrive as a Splunk Cybersecurity Defense Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, typically supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is essential. Strong analytical thinking, problem-solving abilities, and effective communication are important soft skills for collaborating with teams and responding to security incidents. These skills and qualities are critical for quickly identifying, investigating, and mitigating cyber threats to protect organizational assets.

What is the difference between Splunk Cybersecurity Defense Analyst vs Security Operations Center (SOC) Analyst?

AspectSplunk Cybersecurity Defense AnalystSecurity Operations Center (SOC) Analyst
CertificationsSplunk certifications, CompTIA Security+CompTIA Security+, GIAC certifications
Work EnvironmentPrimarily uses Splunk platform for data analysisMonitors security alerts across various tools in a SOC
Industry UsageFinancial, healthcare, tech sectors leveraging SplunkBroadly in all sectors with security teams
Job FocusAnalyzing security data with Splunk, threat detectionMonitoring, incident response, alert management

While both roles focus on cybersecurity, the Splunk Cybersecurity Defense Analyst specializes in using Splunk for data analysis and threat detection, whereas the SOC Analyst performs broader security monitoring and incident response across multiple tools. The roles often overlap but differ in platform focus and scope of responsibilities.

What are popular job titles related to Splunk Cybersecurity Defense Analyst jobs in Raleigh, NC?

For Splunk Cybersecurity Defense Analyst jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Splunk Cybersecurity Defense Analyst jobs in Raleigh, NC look for?

The top searched job categories for Splunk Cybersecurity Defense Analyst jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Splunk Cybersecurity Defense Analyst jobs?

Cities near Raleigh, NC with the most Splunk Cybersecurity Defense Analyst job openings:

Infographic showing various Splunk Cybersecurity Defense Analyst job openings in Raleigh, NC as of August 2026, with employment types broken down into 91% Full Time, 6% Part Time, 2% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $96,625 per year, or $46.5 per hour.

$105 - $120/hr

Other

Medical, Dental, Vision, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Zachary Piper Solutions is seeking a SIEM Engineer to join a leading client in the cybersecurity and defense industry in the RTP area. The SIEM Engineer role is a hybrid position requiring onsite presence on Tuesdays and Thursdays. The SIEM Engineer is best suited for a security professional with strong Splunk expertise, AWS exposure, and experience in SOC or incident response environments who thrives in a fast-paced, mission-driven setting.

Responsibilities of the SIEM Engineer include:
  • Engineer and enhance Splunk Enterprise Security detections, dashboards, and correlation searches to strengthen threat visibility
  • Build and support automation workflows and playbooks within Splunk SOAR to streamline response efforts
  • Integrate and normalize diverse security data sources into Splunk while ensuring data quality and performance optimization
  • Partner with SOC and engineering teams to refine detection capabilities and improve operational efficiency across the environment
  • Lead and support incident investigations, coordinating response actions and contributing to continuous monitoring coverage
Requirements of the SIEM Engineer include:
  • Active Secret Clearance
  • 3+ years of experience in SIEM engineering, SOC operations, or incident response
  • Advanced proficiency with Splunk, including writing complex SPL queries and building production-grade dashboards (similar to Ashley Brown-level experience)
  • Experience integrating AWS services (such as AWS Security Hub) and other security tools into a centralized SIEM platform
  • Strong understanding of data onboarding, CIM normalization, and Splunk knowledge objects, with the ability to operate in high-pressure environments
  • Ability to work onsite twice weekly in RTP – Tuesday and Thursday
Compensation for the SIEM Engineer include:
  • $105,000 – 120,000 annually
  • Full Comprehensive Benefits: Health, Vision, Dental, PTO, Paid Holiday and Sick Leave if Required by Law.
  • This job opens for applications on 8/21/2026. Applications for this job will be accepted for at least 30 days from the posting date.

Keywords: SIEM Engineer, Splunk, SOC, Incident Response, AWS, Security Operations, Hybrid, Fulton, MD

#J-18808-Ljbffr