Security Engineer III, SIEM Engineer
Crowdstrike
Cybersecurity Analysis
Cybersecurity Integration
Cybersecurity Tools
Endpoint Security
Incident Response
Information Security
InfoSec
Investigative Skills
Log Management
Mitre Att&ck
Palo Alto Xsiam
Security Information And Event Management
Security Monitoring
Security Operations
Security Threat Detection
Siem
Splunk
Job Description
Deloitte’s Cyber Defense and Resilience team is seeking a SIEM Engineer to strengthen security monitoring and detection engineering across complex enterprise environments. In this role, you will help improve alert fidelity, support incident analysis, and build reliable SIEM content that enhances how teams detect and respond to suspicious activity.
This position is based in Rosslyn, VA with remote flexibility. The estimated annual salary range is $102,500 to $188,900. You may also be eligible for a discretionary annual incentive program, subject to program rules and factors including individual and organizational performance.
Work you’ll do
- Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports
- Analyze security events and log data to identify suspicious activity, support investigations, and expand detection coverage
- Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
- Partner with cybersecurity teams to support use case development, threat detection, and incident triage and response activities
- Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery
Requirements
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related technical field
- Active Secret Clearance
- 3+ years of experience in cybersecurity, security operations, or SIEM engineering
- 3+ years of experience with at least one: Splunk, Palo Alto Networks XSIAM, or CrowdStrike NG SIEM
- 2+ years experience in creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a SIEM platform
- 2+ years experience reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
- Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required
- Ability to travel up to 20% on average based on work and client needs
- Willingness to work at client onsite or a Deloitte office for up to 5 days per week
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future
Skills and strengths
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams and manage/prioritize multiple tasks in a fast-paced environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines and provide clear guidance to others
Preferred
- 2+ years supporting enterprise monitoring in a Security Operations Center
- Experience onboarding and normalizing log sources in a SIEM platform
- Experience mapping detections to MITRE ATT&CK techniques
- Experience with cloud security monitoring in Amazon Web Services, Microsoft Azure, or Google Cloud Platform
- Hands-on experience with scripting or query languages used for detection and log analysis
- Security certification such as CompTIA Security+ or GIAC certification
Technologies
- Splunk
- Palo Alto XSIAM
- CrowdStrike NG SIEM
- Security Information and Event Management platform
- Splunk certification, Palo Alto Networks certification, CrowdStrike certification
- MITRE ATT&CK