1

Splunk Siem Jobs in Michigan (NOW HIRING)

... as Splunk or Cyber Security systems such as SIEM (Security Information and Event Management) such as IBM QRadar Experience with multiple of the following network management systems: TFTP, Syslog ...

... SIEM, XDR, and MDR platforms. • Identify gaps in logging and telemetry and work with teams to ... Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms ...

Lead SOC Analyst

Grand Rapids, MI · On-site

$90 - $120/hr

Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...

Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...

Develop and tune detection rules within SIEM, XDR, and MDR platforms. * Identify gaps in logging ... Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience ...

Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...

Experience with security information and event management (SIEM) platforms such as Splunk, Sentinel, or similar (Preferred) * Knowledge of scripting and automation using Python, PowerShell, or ...

Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...

Experience with SIEM platforms (Splunk, Sentinel, or similar) * Exposure to high-performance computing, AI infrastructure, or GPU-based systems * Experience with configuration management or ...

Splunk Siem information

What is the difference between Splunk Siem vs Splunk Security Analyst?

AspectSplunk SiemSplunk Security Analyst
Primary RoleMonitoring, analyzing, and managing security data using Splunk SIEM toolsInterpreting security data, investigating threats, and responding to security incidents
Required SkillsSplunk SIEM configuration, log analysis, security monitoringSecurity incident response, threat detection, Splunk analysis
CertificationsSplunk Certified User/Power User, Security certificationsCompTIA Security+, CISSP, Splunk certifications
Work EnvironmentSecurity operations centers, IT departmentsSecurity teams, incident response units

Splunk Siem professionals focus on configuring and maintaining Splunk SIEM systems for security monitoring, while Splunk Security Analysts interpret security data, investigate threats, and respond to incidents. Both roles require knowledge of Splunk tools and security principles, but the Security Analyst role emphasizes active threat response and analysis.

What are popular job titles related to Splunk Siem jobs in Michigan? For Splunk Siem jobs in Michigan, the most frequently searched job titles are:
What cities in Michigan are hiring for Splunk Siem jobs? Cities in Michigan with the most Splunk Siem job openings:

OnSite Cybersecurity Custodian

Black & Veatch

Ann Arbor, MI • On-site

Full-time

Re-posted 15 days ago


Black & Veatch rating

8.9

Company rating: 8.9 out of 10

Based on 19 frontline employees who took The Breakroom Quiz

53rd of 443 rated engineering


Job description

Job Summary:
Black & Veatch is an employee-owned company focused on sustainable infrastructure and engineering solutions. They are seeking a full-time on-site Cybersecurity Custodian to manage cybersecurity execution for a new Power Plant project, ensuring systems are secured and all work is documented for audit readiness.
Responsibilities:
• Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT cybersecurity program, including tracking requirements, planned actions, and completion status and report status of activities to BV Senior Cybersecurity Consultants for review and approvals
• Build and maintain an organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable.
• Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, and sign-offs as required.
• Support pre-CFAT readiness and participate in vendor CFAT activities as required (travel required).
• Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations.
• Track and close cyber-related FAT punch items; ensure retests and final evidence are captured and filed.
• Verify and document required access controls including MFA for remote access, least privilege, and role-based access models.
• Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes.
• Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references).
• Track configuration baselines, redlines, and as-built updates throughout construction and commissioning.
• Coordinate change documentation and evidence, including post-change backup capture and validation.
• Enforce and document removable media and transient device controls in line with Owner policies and site procedures.
• Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention.
• Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met).
• Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, and forwarding architecture.
• Support readiness for NIDS/span port configuration and event forwarding requirements.
• Validate and document that logging is enabled, time-synchronized, and functioning without impacting system performance.
• Verify backup procedures are in place for OT assets and that backups are created after major changes (patching, configuration updates).
• Support restoration testing where required; ensure offline backup handling meets custody and storage requirements.
• Track encrypted portable hard drives / backup media custody and handover documentation where applicable.
• Maintain cyber escalation contacts and on-site reporting procedures.
• Support documentation of cybersecurity events, policy violations, corrective actions, and evidence of remediation steps.
• Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records.
• Track and maintain evidence for required cybersecurity awareness training completion.
• Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations).
• Conduct periodic verification that access authorizations remain current and justified.
Qualifications:
Required:
• Bachelor’s Degree or relevant work experience.
• 4+ years experience in a business/consulting environment.
• All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
• Certifications related to area of expertise, where applicable preferred.
Preferred:
• 3+ years supporting industrial/power generation control systems or OT environments.
• Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP).
• Practical knowledge of OT networking fundamentals such as: IP addressing, VLANs, firewall concepts, routing basics.
• Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design.
• Ability to work on-site in Beech Island, SC for 12+ months (typical 5x8 with occasional off-hours during cutovers).
• Willingness to travel to vendor facilities for CFAT support. Occasional travel for planning/working sessions may be requested. Eligible to meet badging/background/site access requirements.
• Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling.
• Experience supporting FAT/commissioning on large capital projects (power generation or similar).
• Strong documentation discipline—ability to produce clear procedures, logs, checklists, and evidence packages.
• Experience working with vendors and multi-discipline teams in construction/commissioning environments.
Company:
Black & Veatch is an engineering, consulting, and construction company. Founded in 1915, the company is headquartered in Overland Park, USA, with a team of 10001+ employees. The company is currently Late Stage.

What Black & Veatch employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Black & Veatch logo

About Black & Veatch

Sourced by ZipRecruiter

Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.

Industry

Civil engineering construction

Company size

10,000+ Employees

Headquarters location

Overland Park, KS, US

Year founded

1915