1

Splunk Siem Engineer Jobs in Michigan (NOW HIRING)

Shell, Perl, other -Experience with SQL, and basic web programming experience Experience ... Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as ...

Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...

Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance ... Experience administering developer and infrastructure platforms such as GitHub, Tailscale, or ...

... engineering and security teams to improve detection logic and use cases. • Develop and tune ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...

Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...

Detection Engineering and Monitoring * Collaborate with engineering and security teams to improve ... Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ...

Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...

Collaborates with development operations and engineering teams to embed security into continuous ... Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel ...

Splunk Siem Engineer information

See Michigan salary details

$47.9K

$110.7K

$158.9K

How much do splunk siem engineer jobs pay per year?

As of Jul 26, 2026, the average yearly pay for splunk siem engineer in Michigan is $110,680.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,769.00 and $127,774.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer, and why are they important?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.
What cities in Michigan are hiring for Splunk Siem Engineer jobs? Cities in Michigan with the most Splunk Siem Engineer job openings:
OnSite Cybersecurity Custodian

OnSite Cybersecurity Custodian

Black & Veatch

Ann Arbor, MI • On-site

Full-time

Posted 3 days ago


Black & Veatch rating

8.9

Company rating: 8.9 out of 10

Based on 19 frontline employees who took The Breakroom Quiz

54th of 442 rated engineering


Job description

Job Summary:
Black & Veatch is an employee-owned company focused on sustainable infrastructure and engineering solutions. They are seeking a full-time on-site Cybersecurity Custodian to manage cybersecurity execution for a new Power Plant project, ensuring systems are secured and all work is documented for audit readiness.
Responsibilities:
• Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT cybersecurity program, including tracking requirements, planned actions, and completion status and report status of activities to BV Senior Cybersecurity Consultants for review and approvals
• Build and maintain an organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable.
• Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, and sign-offs as required.
• Support pre-CFAT readiness and participate in vendor CFAT activities as required (travel required).
• Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations.
• Track and close cyber-related FAT punch items; ensure retests and final evidence are captured and filed.
• Verify and document required access controls including MFA for remote access, least privilege, and role-based access models.
• Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes.
• Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references).
• Track configuration baselines, redlines, and as-built updates throughout construction and commissioning.
• Coordinate change documentation and evidence, including post-change backup capture and validation.
• Enforce and document removable media and transient device controls in line with Owner policies and site procedures.
• Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention.
• Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met).
• Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, and forwarding architecture.
• Support readiness for NIDS/span port configuration and event forwarding requirements.
• Validate and document that logging is enabled, time-synchronized, and functioning without impacting system performance.
• Verify backup procedures are in place for OT assets and that backups are created after major changes (patching, configuration updates).
• Support restoration testing where required; ensure offline backup handling meets custody and storage requirements.
• Track encrypted portable hard drives / backup media custody and handover documentation where applicable.
• Maintain cyber escalation contacts and on-site reporting procedures.
• Support documentation of cybersecurity events, policy violations, corrective actions, and evidence of remediation steps.
• Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records.
• Track and maintain evidence for required cybersecurity awareness training completion.
• Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations).
• Conduct periodic verification that access authorizations remain current and justified.
Qualifications:
Required:
• Bachelor’s Degree or relevant work experience.
• 4+ years experience in a business/consulting environment.
• All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
• Certifications related to area of expertise, where applicable preferred.
Preferred:
• 3+ years supporting industrial/power generation control systems or OT environments.
• Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP).
• Practical knowledge of OT networking fundamentals such as: IP addressing, VLANs, firewall concepts, routing basics.
• Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design.
• Ability to work on-site in Beech Island, SC for 12+ months (typical 5x8 with occasional off-hours during cutovers).
• Willingness to travel to vendor facilities for CFAT support. Occasional travel for planning/working sessions may be requested. Eligible to meet badging/background/site access requirements.
• Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling.
• Experience supporting FAT/commissioning on large capital projects (power generation or similar).
• Strong documentation discipline—ability to produce clear procedures, logs, checklists, and evidence packages.
• Experience working with vendors and multi-discipline teams in construction/commissioning environments.
Company:
Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the company is headquartered in Overland Park, USA, with a team of 10001+ employees. The company is currently Late Stage.

What Black & Veatch employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Black & Veatch logo

About Black & Veatch

Sourced by ZipRecruiter

Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.

Industry

Civil engineering construction

Company size

10,000+ Employees

Headquarters location

Overland Park, KS, US

Year founded

1915