... Splunk/SIEM, including log sources, retention requirements, and forwarding architecture. • Support readiness for NIDS/span port configuration and event forwarding requirements. • Validate and ...
... Splunk/SIEM, including log sources, retention requirements, and forwarding architecture. • Support readiness for NIDS/span port configuration and event forwarding requirements. • Validate and ...
OT Security Response Engineer
Mount Clemens, MI · On-site
$145K - $234K/yr
Hands-on experience with security tools such as Splunk SIEM, Nozomi, CrowdStrike Falcon * Understanding of regulatory concerns in an OT environment * Experience coordinating response efforts across ...
OT Security Response Engineer
Mount Clemens, MI · On-site
$145K - $234K/yr
Hands-on experience with security tools such as Splunk SIEM, Nozomi, CrowdStrike Falcon * Understanding of regulatory concerns in an OT environment * Experience coordinating response efforts across ...
System Engineer
Dearborn, MI · On-site
... as Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as IBM QRadar Experience with multiple of the following network management systems: TFTP, Syslog ...
System Engineer
Dearborn, MI · On-site
... as Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as IBM QRadar Experience with multiple of the following network management systems: TFTP, Syslog ...
... Splunk, or similar security information and event management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC ...
... Splunk, or similar security information and event management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC ...
... Splunk, or similar security information and event management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC ...
... Splunk, or similar security information and event management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Lead SOC Analyst
Grand Rapids, MI · On-site
... SIEM, XDR, and MDR platforms. • Identify gaps in logging and telemetry and work with teams to ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...
Lead SOC Analyst
Grand Rapids, MI · On-site
... SIEM, XDR, and MDR platforms. • Identify gaps in logging and telemetry and work with teams to ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Monitor and analyze security events using SIEM tools (e.g., Splunk) * Assist in cybersecurity incident response, including initial triage, containment, and documentation * Conduct vulnerability scans ...
Quick apply
Monitor and analyze security events using SIEM tools (e.g., Splunk) * Assist in cybersecurity incident response, including initial triage, containment, and documentation * Conduct vulnerability scans ...
Manager, IT Security
Southfield, MI · On-site
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Manager, IT Security
Southfield, MI · On-site
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Manager, IT Security
Southfield, MI · On-site
... management (SIEM) platforms such as Splunk, Sentinel, or similar • Knowledge of scripting and automation using Python, PowerShell, or similar • Preferred Certifications/Licensures:(AWS ...
Manager, IT Security
Southfield, MI · On-site
... management (SIEM) platforms such as Splunk, Sentinel, or similar • Knowledge of scripting and automation using Python, PowerShell, or similar • Preferred Certifications/Licensures:(AWS ...
Manager, IT Security
Southfield, MI · On-site
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Manager, IT Security
Southfield, MI · On-site
Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...
Quick apply
Senior Network & Systems Engineer
Ann Arbor, MI · On-site
$125K - $155K/yr
Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...
Splunk Siem information
What is the difference between Splunk Siem vs Splunk Security Analyst?
| Aspect | Splunk Siem | Splunk Security Analyst |
|---|---|---|
| Primary Role | Monitoring, analyzing, and managing security data using Splunk SIEM tools | Interpreting security data, investigating threats, and responding to security incidents |
| Required Skills | Splunk SIEM configuration, log analysis, security monitoring | Security incident response, threat detection, Splunk analysis |
| Certifications | Splunk Certified User/Power User, Security certifications | CompTIA Security+, CISSP, Splunk certifications |
| Work Environment | Security operations centers, IT departments | Security teams, incident response units |
Splunk Siem professionals focus on configuring and maintaining Splunk SIEM systems for security monitoring, while Splunk Security Analysts interpret security data, investigate threats, and respond to incidents. Both roles require knowledge of Splunk tools and security principles, but the Security Analyst role emphasizes active threat response and analysis.
Black & Veatch rating
8.9
Based on 19 frontline employees who took The Breakroom Quiz
53rd of 443 rated engineering
Job description
Black & Veatch is an employee-owned company focused on sustainable infrastructure and engineering solutions. They are seeking a full-time on-site Cybersecurity Custodian to manage cybersecurity execution for a new Power Plant project, ensuring systems are secured and all work is documented for audit readiness.
Responsibilities:
• Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT cybersecurity program, including tracking requirements, planned actions, and completion status and report status of activities to BV Senior Cybersecurity Consultants for review and approvals
• Build and maintain an organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable.
• Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, and sign-offs as required.
• Support pre-CFAT readiness and participate in vendor CFAT activities as required (travel required).
• Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations.
• Track and close cyber-related FAT punch items; ensure retests and final evidence are captured and filed.
• Verify and document required access controls including MFA for remote access, least privilege, and role-based access models.
• Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes.
• Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references).
• Track configuration baselines, redlines, and as-built updates throughout construction and commissioning.
• Coordinate change documentation and evidence, including post-change backup capture and validation.
• Enforce and document removable media and transient device controls in line with Owner policies and site procedures.
• Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention.
• Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met).
• Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, and forwarding architecture.
• Support readiness for NIDS/span port configuration and event forwarding requirements.
• Validate and document that logging is enabled, time-synchronized, and functioning without impacting system performance.
• Verify backup procedures are in place for OT assets and that backups are created after major changes (patching, configuration updates).
• Support restoration testing where required; ensure offline backup handling meets custody and storage requirements.
• Track encrypted portable hard drives / backup media custody and handover documentation where applicable.
• Maintain cyber escalation contacts and on-site reporting procedures.
• Support documentation of cybersecurity events, policy violations, corrective actions, and evidence of remediation steps.
• Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records.
• Track and maintain evidence for required cybersecurity awareness training completion.
• Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations).
• Conduct periodic verification that access authorizations remain current and justified.
Qualifications:
Required:
• Bachelor’s Degree or relevant work experience.
• 4+ years experience in a business/consulting environment.
• All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
• Certifications related to area of expertise, where applicable preferred.
Preferred:
• 3+ years supporting industrial/power generation control systems or OT environments.
• Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP).
• Practical knowledge of OT networking fundamentals such as: IP addressing, VLANs, firewall concepts, routing basics.
• Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design.
• Ability to work on-site in Beech Island, SC for 12+ months (typical 5x8 with occasional off-hours during cutovers).
• Willingness to travel to vendor facilities for CFAT support. Occasional travel for planning/working sessions may be requested. Eligible to meet badging/background/site access requirements.
• Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling.
• Experience supporting FAT/commissioning on large capital projects (power generation or similar).
• Strong documentation discipline—ability to produce clear procedures, logs, checklists, and evidence packages.
• Experience working with vendors and multi-discipline teams in construction/commissioning environments.
Company:
Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the company is headquartered in Overland Park, USA, with a team of 10001+ employees. The company is currently Late Stage.
What Black & Veatch employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Black & Veatch
Sourced by ZipRecruiter
Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.
Industry
Civil engineering construction
Company size
10,000+ Employees
Headquarters location
Overland Park, KS, US
Year founded
1915