... Splunk/SIEM, including log sources, retention requirements, and forwarding architecture. • ... Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the ...
... Splunk/SIEM, including log sources, retention requirements, and forwarding architecture. • ... Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the ...
OT Security Response Engineer
$145K - $234K/yr
Hands-on experience with security tools such as Splunk SIEM, Nozomi, CrowdStrike Falcon ... engineering, and/orIT withsubject matterexpertiseinareassuch asthreat detection ...
OT Security Response Engineer
$145K - $234K/yr
Hands-on experience with security tools such as Splunk SIEM, Nozomi, CrowdStrike Falcon ... engineering, and/orIT withsubject matterexpertiseinareassuch asthreat detection ...
Shell, Perl, other -Experience with SQL, and basic web programming experience Experience ... Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as ...
Shell, Perl, other -Experience with SQL, and basic web programming experience Experience ... Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as ...
... SIEM query from memory, and who instinctively knows when an alert is misfiring and exactly why ... Platform-specific certifications such as CrowdStrike Certified Falcon Administrator, Splunk Core ...
... SIEM query from memory, and who instinctively knows when an alert is misfiring and exactly why ... Platform-specific certifications such as CrowdStrike Certified Falcon Administrator, Splunk Core ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...
Quick apply
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...
Lead SOC Analyst
Grand Rapids, MI · On-site
... engineering and security teams to improve detection logic and use cases. • Develop and tune ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...
Lead SOC Analyst
Grand Rapids, MI · On-site
... engineering and security teams to improve detection logic and use cases. • Develop and tune ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...
Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...
Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Manager, IT Security
Southfield, MI · On-site
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Manager, IT Security
Southfield, MI · On-site
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Manager, IT Security
Southfield, MI · On-site
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Manager, IT Security
Southfield, MI · On-site
Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...
Manager, IT Security
Southfield, MI · On-site
... and engineering teams to embed security into continuous integration and continuous delivery ... SIEM) platforms such as Splunk, Sentinel, or similar • Knowledge of scripting and automation ...
Manager, IT Security
Southfield, MI · On-site
... and engineering teams to embed security into continuous integration and continuous delivery ... SIEM) platforms such as Splunk, Sentinel, or similar • Knowledge of scripting and automation ...
Splunk Siem Engineer information
See Michigan salary details
$47.9K - $58K
1% of jobs
$58K - $68.1K
2% of jobs
$68.1K - $78.2K
7% of jobs
$78.2K - $88.3K
11% of jobs
$91.4K is the 25th percentile. Wages below this are outliers.
$88.3K - $98.4K
13% of jobs
The median wage is $107.6K / yr.
$98.4K - $108.5K
18% of jobs
$108.5K - $118.6K
19% of jobs
$123.3K is the 75th percentile. Wages above this are outliers.
$118.6K - $128.7K
9% of jobs
$128.7K - $138.8K
7% of jobs
$138.8K - $148.8K
6% of jobs
$148.8K - $158.9K
6% of jobs
$47.9K
$110.7K
$158.9K
How much do splunk siem engineer jobs pay per year?
What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer, and why are they important?
What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?
What is the difference between Splunk Siem Engineer vs Security Analyst?
| Aspect | Splunk Siem Engineer | Security Analyst |
|---|---|---|
| Certifications | Splunk Certified Power User, Splunk Certified Admin | CompTIA Security+, GIAC Security Essentials |
| Work Environment | Focus on configuring, maintaining, and optimizing Splunk SIEM tools | Monitor security alerts, investigate incidents, and implement security measures |
| Industry Usage | Primarily in cybersecurity, IT operations, and compliance | Across cybersecurity teams, incident response, and risk management |
The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.
What does a Splunk SIEM Engineer do?
Black & Veatch rating
8.9
Based on 19 frontline employees who took The Breakroom Quiz
54th of 442 rated engineering
Job description
Black & Veatch is an employee-owned company focused on sustainable infrastructure and engineering solutions. They are seeking a full-time on-site Cybersecurity Custodian to manage cybersecurity execution for a new Power Plant project, ensuring systems are secured and all work is documented for audit readiness.
Responsibilities:
• Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT cybersecurity program, including tracking requirements, planned actions, and completion status and report status of activities to BV Senior Cybersecurity Consultants for review and approvals
• Build and maintain an organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable.
• Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, and sign-offs as required.
• Support pre-CFAT readiness and participate in vendor CFAT activities as required (travel required).
• Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations.
• Track and close cyber-related FAT punch items; ensure retests and final evidence are captured and filed.
• Verify and document required access controls including MFA for remote access, least privilege, and role-based access models.
• Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes.
• Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references).
• Track configuration baselines, redlines, and as-built updates throughout construction and commissioning.
• Coordinate change documentation and evidence, including post-change backup capture and validation.
• Enforce and document removable media and transient device controls in line with Owner policies and site procedures.
• Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention.
• Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met).
• Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, and forwarding architecture.
• Support readiness for NIDS/span port configuration and event forwarding requirements.
• Validate and document that logging is enabled, time-synchronized, and functioning without impacting system performance.
• Verify backup procedures are in place for OT assets and that backups are created after major changes (patching, configuration updates).
• Support restoration testing where required; ensure offline backup handling meets custody and storage requirements.
• Track encrypted portable hard drives / backup media custody and handover documentation where applicable.
• Maintain cyber escalation contacts and on-site reporting procedures.
• Support documentation of cybersecurity events, policy violations, corrective actions, and evidence of remediation steps.
• Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records.
• Track and maintain evidence for required cybersecurity awareness training completion.
• Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations).
• Conduct periodic verification that access authorizations remain current and justified.
Qualifications:
Required:
• Bachelor’s Degree or relevant work experience.
• 4+ years experience in a business/consulting environment.
• All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
• Certifications related to area of expertise, where applicable preferred.
Preferred:
• 3+ years supporting industrial/power generation control systems or OT environments.
• Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP).
• Practical knowledge of OT networking fundamentals such as: IP addressing, VLANs, firewall concepts, routing basics.
• Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design.
• Ability to work on-site in Beech Island, SC for 12+ months (typical 5x8 with occasional off-hours during cutovers).
• Willingness to travel to vendor facilities for CFAT support. Occasional travel for planning/working sessions may be requested. Eligible to meet badging/background/site access requirements.
• Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling.
• Experience supporting FAT/commissioning on large capital projects (power generation or similar).
• Strong documentation discipline—ability to produce clear procedures, logs, checklists, and evidence packages.
• Experience working with vendors and multi-discipline teams in construction/commissioning environments.
Company:
Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the company is headquartered in Overland Park, USA, with a team of 10001+ employees. The company is currently Late Stage.
What Black & Veatch employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Black & Veatch
Sourced by ZipRecruiter
Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.
Industry
Civil engineering construction
Company size
10,000+ Employees
Headquarters location
Overland Park, KS, US
Year founded
1915