About this opportunity
Insight Global lists this Cybersecurity Engineer III opportunity in richmond, Virginia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Insight Global is seeking a Cybersecurity Engineer 3 for a top public sector transportation client. This will be an ongoing year-long contract engagement with extension potential based on overall fit and performance, and the onsite expectation is 3 days per week in Richmond, VA. This candidate will support and enhance a Splunk Enterprise Security environment by monitoring, detecting, investigating, and responding to cybersecurity threats across the organization. The ideal candidate will bring strong experience in SIEM operations, threat hunting, SPL query development, incident response, log analysis, and security monitoring. This individual will work closely with infrastructure, network, and IT teams to strengthen security visibility, onboard new log sources, improve threat detection capabilities, and ensure compliance with established security standards. This is an excellent opportunity to work on advanced cybersecurity initiatives while helping protect critical enterprise infrastructure from emerging threats.
Day-to-Day:
Monitor network traffic, endpoint logs, and cloud security events for suspicious activity
Create, maintain, and tune Splunk correlation searches, alerts, and dashboards
Investigate security incidents and perform threat analysis using forensic evidence
Collaborate with IT and network teams to remediate security threats
Develop and enhance detection use cases and incident response playbooks
Leverage threat intelligence and MITRE ATT&CK methodologies to improve security posture
Onboard new data sources into Splunk and ensure proper log normalization and integrity
Generate compliance reports and support audit readiness efforts
Improve detection capabilities while reducing false positives across the SIEM environment
Must-Haves:
8+ years of hands-on cybersecurity experience operating, building, and investigating threats within a SIEM or Splunk environment
8+ years of experience writing SPL (Splunk Processing Language) queries
Strong understanding of networking, firewalls, EDR, and cloud platforms (AWS, Azure, or GCP)
Experience with threat detection, threat hunting, and incident response
Knowledge of security frameworks including MITRE ATT&CK
Understanding of compliance standards such as NIST, HIPAA, and SOC 2
Excellent critical thinking, problem-solving, and communication skills
Ability to operate effectively under pressure while managing multiple security tickets and incidents
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field
Plusses:
Splunk Core Certified User certification
Splunk Core Certified Advanced Power User certification
Additional cybersecurity certifications
Advanced experience with Splunk Enterprise Security
Worksite address
richmond, VA, 23214, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.