1

Splunk Siem Engineer Jobs (NOW HIRING)

Lead SIEM Engineer

Buffalo, NY ยท Hybrid

$116.40K - $194K/yr

As a Lead SIEM Engineer, you will be responsible for leading the design, implementation, and ... In-depth knowledge of SIEM technologies (e.g., Splunk, IBM QRadar, Sumo Logic, Securonix ...

Lead SIEM Engineer

Buffalo, NY ยท On-site

$116.40K - $194K/yr

As a Lead SIEM Engineer, you will be responsible for leading the design, implementation, and ... In-depth knowledge of SIEM technologies (e.g., Splunk, IBM QRadar, Sumo Logic, Securonix ...

Lead SIEM Engineer

Bridgeport, CT ยท On-site

$142.10K - $236.80K/yr

As a Lead SIEM Engineer, you will be responsible for leading the design, implementation, and ... In-depth knowledge of SIEM technologies (e.g., Splunk, IBM QRadar, Sumo Logic, Securonix ...

Lead SIEM Engineer

Wilmington, DE ยท Hybrid

$128.10K - $213.50K/yr

As a Lead SIEM Engineer, you will be responsible for leading the design, implementation, and ... In-depth knowledge of SIEM technologies (e.g., Splunk, IBM QRadar, Sumo Logic, Securonix ...

Senior Cybersecurity Engineer

Charlotte, NC ยท Hybrid

$111.80K - $153.30K/yr

Job Summary We are seeking a highly experienced Senior Splunk SIEM / Cybersecurity Engineer to design, implement, optimize, and manage enterprise-scale security monitoring and analytics platforms.

next page

Showing results 1-20

Splunk Siem Engineer information

See salary details

$54.5K

$126K

$181K

How much do splunk siem engineer jobs pay per year?

As of May 29, 2026, the average yearly pay for splunk siem engineer in the United States is $126,034.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,500.00 and $145,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer, and why are they important?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

More about Splunk Siem Engineer jobs
What cities are hiring for Splunk Siem Engineer jobs? Cities with the most Splunk Siem Engineer job openings:
What states have the most Splunk Siem Engineer jobs? States with the most job openings for Splunk Siem Engineer jobs include:
What job categories do people searching Splunk Siem Engineer jobs look for? The top searched job categories for Splunk Siem Engineer jobs are:
Infographic showing various Splunk Siem Engineer job openings in the United States as of May 2026, with employment types broken down into 96% Full Time, and 4% Part Time. Highlights an 10% Physical, 29% Hybrid, and 61% Remote job distribution, with an average salary of $126,034 per year, or $60.6 per hour.
Splunk SIEM Engineer

Splunk SIEM Engineer

Resource Management Concepts, Inc.

Crane, IN โ€ข On-site

Full-time

Medical, Retirement, PTO

Posted 28 days ago


Job description

Position Overview

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.

We are seeking a skilled Splunk SIEM Engineer to lead the evolution of our Splunk environment into a fully operational, enterprise-grade Security Information and Event Management (SIEM) platform. This role will be responsible for both the build-out and ongoing operations of the platform, ensuring it delivers reliable, actionable security insights and supports evolving cybersecurity initiatives. This is a hybrid position that requires regular onsite presence in Crane, Indiana.

Key Responsibilities

  • Lead the transformation of the Splunk environment into a fully functional SIEM platform
  • Manage and optimize the data ingestion pipeline:
    • Audit existing data sources for relevance and efficiency
    • Eliminate unnecessary data ingestion to control licensing costs
    • Onboard and integrate new data sources
  • Parse, normalize, and map ingested data to the Splunk Common Information Model (CIM)
  • Configure, maintain, and optimize Splunk Enterprise Security (ES)
  • Configure, maintain, and optimize Splunk security orchestration, automation, and response platform (SOAR)
  • Develop and maintain correlation searches, detections, and use cases
  • Create and tune alerts to improve fidelity and reduce false positives
  • Build dashboards and visualizations for operational awareness and trend analysis
  • Monitor overall platform health and performance
  • Perform system upgrades, patching, and capacity planning
  • Manage intra Splunk certificates
  • Manage the lifecycle of security content:
    • Continuously refine detections and correlation rules
    • Enhance visibility and detection coverage based on emerging threats
  • Ensure consistent SIEM operations regardless of hosting environment or infrastructure ownership
  • Support ongoing security operations and future cybersecurity initiatives

Requirements

Required Qualifications

  • A SecurityX, CASP, or equivalent DoD 8140 IAT-3 certification is required.
  • Security Clearance: An interim DoD Secret security clearance or higher is required to start. Applicant selected may be subject to a security investigation and must meet eligibility requirements for access to classified information.
  • Hands-on experience with Splunk Enterprise and Splunk Enterprise Security (ES)
  • Strong understanding of SIEM architecture, design, and operations
  • Experience with log ingestion, parsing, normalization, and CIM mapping
  • Proficiency in developing correlation searches, alerts, and dashboards
  • Experience tuning SIEM content to reduce false positives and improve detection accuracy
  • Familiarity with data onboarding strategies and license optimization
  • Knowledge of cybersecurity principles, threat detection, and incident response
  • Experience with system administration tasks including patching, upgrades, and performance monitoring

Preferred Qualifications

  • Experience operating Splunk in distributed or multi-tenant environments
  • Knowledge of data pipelines and log forwarding technologies (e.g., syslog, APIs, forwarders)
  • Familiarity with frameworks such as MITRE ATT&CK
  • Experience supporting Zero Trust or advanced security architectures
  • Preferred certifications (e.g., Splunk Certified Admin, Splunk ES Certified, Security+)

Benefits

At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.

RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.

Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements.