Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance)
Job Description
Responsibilities
- Craft and tailor Splunk dashboards, applications, alerts, and visualizations to boost SOC performance and maturity.
- Develop advanced reporting and visualizations to support SOC operations and stakeholder needs.
- Build, test, document, implement, and tune security content throughout its lifecycle, including data models, dashboards, correlation logic, searches, and alert notifications.
- Perform advanced searches and analysis in large-scale SIEM environments.
- Analyze, trend, and filter security log data from multiple sources, including firewalls, IDS/IPS, hosts, load balancers, and other security and monitoring tools.
- Develop and enhance custom SPL using macros, lookups, regex, and network-based logic.
- Support SOP development, updates, implementation, and training.
- Mentor junior and mid-level analysts on SOC processes, content development, and detection practices.
- Identify indicators of compromise (IOCs) and network traffic indicators to detect anomalous activity, including lateral movement.
- Support enterprise logging use cases across application, operating system, and security device logs.
Requirements
- Bachelor's Degree required.
- Active Secret Clearance required.
- Ability to work onsite in Herndon, VA up to 3 days a week.
- 3+ years of experience in the following areas:
- Extensive experience designing and configuring SIEM applications, dashboards, and visualizations for medium-to-large SOC environments.
- Extensive experience developing advanced reporting, searches, alerts, and dashboards in Splunk or similar enterprise SIEM platforms.
- Extensive experience analyzing high volumes of security log data from diverse enterprise security technologies.
- Experience optimizing SIEM security content and implementing SOC processes and SOPs.
- Experience mentoring junior and mid-level analysts.
- Experience with enterprise logging solutions, regex, custom log parsing, and network security tools.
- Ability to travel 15 percent on average based on client needs.
- Must be legally authorized to work in the United States without employer sponsorship now or in the future.
- Candidate must possess one of the following certifications: CISSP, GCIH, GCFA, GPEN, GWAPT, GCIA, or equivalent.
Technologies
- Splunk
- SPL
- regex
Benefits
- Discretionary annual incentive program
- Competitive benefits package for project delivery-focused professionals
The Team
Deloitte's Government & Public Services GPS practice emphasizes impact through people, ideas, technology, and outcomes. It serves federal, state, and local government clients as well as public higher education, bringing fresh perspectives to help agencies anticipate disruption, reimagine possibilities, and fulfill missions.
The Cyber Defense & Resilience offering helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. It supports managing evolving attack surfaces and provides rapid crisis and cyber incident response to ensure readiness, response, and recovery from business disruptions.
The Project Delivery Talent Model focuses on professionals with specialized skills aligned to current client needs. Team members deliver services directly to clients, with employment tied to project roles and a benefits package that remains competitive for project delivery–focused professionals.