EngineerJobs.io
← Back to all jobs

Job Description

The Security Engineer III (Splunk Architect) role supports Deloitte’s Cyber team by designing, implementing, and optimizing Splunk platforms for security monitoring, visibility, and enterprise logging strategies. The position combines hands-on Splunk engineering with architecture responsibilities to strengthen threat detection and operational resilience.

Responsibilities

  • Design, implement, and optimize Splunk architectures to support security monitoring, log management, and operational analytics.
  • Develop and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business requirements.
  • Integrate data sources into Splunk, including infrastructure, cloud, application, and security technologies.
  • Support use case development for threat detection, incident response, compliance monitoring, and operational visibility.
  • Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • Ability to work onsite up to 5 days per week at the Baltimore, MD location.
  • Experience implementing and supporting Splunk Enterprise or Splunk Cloud.
  • Experience developing Splunk dashboards, reports, alerts, and saved searches.
  • Experience onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools.
  • Working knowledge of SIEM concepts, security monitoring, or threat detection use cases.
  • Working knowledge of TCP/IP, networking protocols, and system log analysis.
  • Experience with Splunk Search Processing Language (SPL), data models, and role-based access controls.
  • One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security.
  • Ability to travel 20% on average based on work, clients, and industries or sectors served.
  • Legally authorized to work in the United States without employer sponsorship, now or in the future.

Preferred Qualifications

  • 1+ years supporting Splunk in AWS, Microsoft Azure, or GCP.
  • 5+ years of experience with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows.
  • 5+ years integrating Splunk with endpoint, identity, firewall, or cloud security tools.
  • 1+ year of experience with Python, automation scripting, or infrastructure as code tools.
  • Experience supporting regulated or federal environments.

Technologies

  • Splunk Enterprise
  • Splunk Cloud
  • Splunk Search Processing Language (SPL)
  • TCP/IP
  • SIEM
  • Splunk dashboards
  • Splunk alerts
  • Splunk reports
  • Saved searches
  • Splunk data models
  • Role-based access controls

Team and Offering

Deloitte’s Cyber team focuses on the unique challenges and opportunities businesses face in cybersecurity. The Cyber Defense & Resilience offering helps manage and protect dynamic attack surfaces and supports rapid crisis and cyber incident response, helping clients prepare for, respond to, and recover from business disruptions.

Compensation and Location

  • Location: Baltimore, MD (onsite)
  • Compensation: USD 102,500 - 188,900 per year
  • Minimum experience: 2 years

Skills for Success

  • Ability to work independently and collaborate as part of a team.
  • Effective written and verbal communication skills.
  • Meticulous attention to detail and quality of work product.
  • Ability to build and sustain professional relationships.
  • Ability to lead projects or workstreams.
  • Ability to manage and prioritize multiple tasks in a fast-paced environment.
  • Strong interpersonal skills and professional demeanor.
  • Ability to meet deadlines.
  • Ability to provide clear guidance to others.

Similar Jobs