Cybersecurity Engineer 3

TOMORROW HIRE

$128K — $170K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in cybersecurity with a focus on SIEM or Splunk environments.
  • Expertise in Splunk Processing Language (SPL) for optimization.
  • Strong understanding of networking, firewalls, EDR, and cloud services (AWS, Azure, GCP).
  • Familiarity with security frameworks and compliance standards (e.g., MITRE ATT&CK, NIST, HIPAA).
  • Proven critical thinking and problem-solving skills, especially under pressure.
  • Bachelor's degree in Computer Science, Cybersecurity, or related fields.
  • Legal authorization to work in the U.S. without sponsorship.

Responsibilities

  • Monitor network traffic and security logs for suspicious activities.
  • Conduct proactive threat hunting using Splunk and analytical methods.
  • Investigate and prioritize security events requiring further analysis.
  • Administer and optimize Splunk correlation searches and alerts.
  • Create effective SPL queries to enhance threat detection.
  • Collaborate on containment and remediation of cybersecurity incidents.
  • Develop threat detection use cases using threat intelligence.

Benefits

  • Onsite work arrangement in Richmond, VA.
  • Contract duration of approximately 10 months from 08/31/2026 to 06/30/2027.
  • Opportunity to develop advanced cyber defense skills in a government context.
  • Exposure to a variety of cyber threat scenarios and compliance requirements.
Full Job Description
Job Title: Cybersecurity Engineer 3
Work Type: Onsite
Location: Richmond, VA 23219
Start Date: 08/31/2026
End Date: 06/30/2027
Industry Category: Information Technology / Government
Employment Type: 1099 Contract
Requisition ID: 807541

Overview

We are seeking an experienced Cybersecurity Engineer to strengthen the agency's cybersecurity operations by developing and implementing advanced cyber defense solutions. This role is responsible for safeguarding enterprise infrastructure, supporting Splunk SIEM operations, detecting and responding to cyber threats, and ensuring security solutions are implemented according to agency standards. The ideal candidate is a highly analytical security professional with deep experience in SIEM operations, threat detection, incident response, and security monitoring.

Application

Applications will be reviewed as received.

Candidates must:
  • Meet all required qualifications.
  • Be available to interview in person.
  • Physically reside within the United States for the duration of the assignment.
  • Be legally authorized to work in the United States without employer sponsorship, now or in the future.

Job Description

The Cybersecurity Engineer will support VDOT's cybersecurity operations by leveraging Splunk Enterprise Security to monitor, detect, investigate, and respond to cybersecurity threats across enterprise environments. This position works closely with infrastructure, networking, and IT teams to improve detection capabilities, onboard new log sources, develop threat detection use cases, and support security compliance initiatives while protecting critical systems and data.

Responsibilities

Threat Detection & Monitoring
  • Continuously monitor network traffic, endpoint activity, cloud environments, and security logs for suspicious behavior and potential security incidents.
  • Perform proactive threat hunting using Splunk Enterprise Security and advanced analytical techniques.
  • Identify, analyze, and prioritize security events requiring investigation.

Splunk SIEM Administration
  • Create, maintain, optimize, and tune Splunk correlation searches, dashboards, alerts, and detection rules.
  • Develop efficient SPL (Splunk Processing Language) queries to improve threat detection and reduce false positives.
  • Support onboarding, parsing, normalization, and validation of new log sources within the SIEM platform.

Incident Response
  • Investigate security incidents and analyze forensic evidence to determine root cause and impact.
  • Collaborate with infrastructure, networking, and IT teams to contain, remediate, and recover from cybersecurity events.
  • Document findings and contribute to continuous improvement of incident response procedures.

Security Engineering & Threat Intelligence
  • Develop and enhance detection use cases and response playbooks using threat intelligence and security frameworks such as MITRE ATT&CK.
  • Support implementation of advanced cyber defense capabilities that strengthen enterprise security posture.
  • Recommend improvements to monitoring, detection, and response processes.

Compliance & Reporting
  • Generate security reports and SIEM metrics supporting audit readiness.
  • Collect and maintain evidence required for security and compliance reviews.
  • Support compliance efforts aligned with recognized security standards and internal policies.


Requirements

Minimum Qualifications
  • Minimum of 8 years of hands-on cybersecurity experience operating, building, and investigating threats within SIEM or Splunk environments.
  • Minimum of 8 years of experience writing and optimizing SPL (Splunk Processing Language).
  • Minimum of 8 years of experience with networking concepts, firewalls, endpoint detection and response (EDR), and cloud platforms such as AWS, Azure, or GCP.
  • Minimum of 8 years of experience applying security frameworks and compliance standards such as MITRE ATT&CK, NIST, HIPAA, or SOC 2.
  • Minimum of 8 years demonstrating excellent critical thinking, problem-solving, communication, and the ability to manage multiple security incidents under pressure.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Must physically reside within the United States for the duration of the assignment.
  • Must attend an in-person interview.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Preferred Qualifications
  • Minimum of 8 years of experience supported by Splunk certifications such as Splunk Core Certified User and Splunk Core Certified Advanced Power User.

Benefits

Compensation

This is a 1099 Contract opportunity.

Pay Rate: $62 - $82 per hour

Schedule
  • Assignment Start Date: 08/31/2026
  • Assignment End Date: 06/30/2027
  • Assignment Duration: Approximately 10 months
  • Work Arrangement: Onsite

Work Location
  • Richmond, VA
  • This position requires full-time onsite attendance.

Similar Jobs

More Jobs at TOMORROW HIRE

More Information Technology Jobs

Find similar Cybersecurity Engineer 3 jobs: