Security Engineer III, Splunk Architect
Analytics
Cloud Platforms
Cybersecurity Tools
Data Analysis
Data Platform
Data Processing
Data Security
Digital Marketing
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Security
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Solution Architecture
Splunk
Splunk Architecture
Splunk Data Models
Splunk Siem
Splunk Soar
Job Description
Design and engineer Splunk-based security monitoring solutions in a hands-on architecture role for Deloitte’s Cyber team.
Responsibilities
- Design, implement, and optimize Splunk architectures for security monitoring, log management, and operational analytics
- Build and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business needs
- Integrate data from infrastructure, cloud, applications, and security technologies into Splunk
- Support use case development for threat detection, incident response, compliance monitoring, and operational visibility
- Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week
- 2+ years of experience with:
- Implementing and supporting Splunk Enterprise or Splunk Cloud
- Developing Splunk dashboards, reports, alerts, and saved searches
- Onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools
- SIEM concepts, security monitoring, or threat detection use cases
- Working knowledge of TCP/IP, networking protocols, and system log analysis
- Splunk SPL, data models, and role-based access controls
- One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security
- Ability to travel 20%, on average, based on work and client/industry needs
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Splunk Enterprise, Splunk Cloud
- Splunk Search Processing Language (SPL)
- SIEM
- Splunk dashboards, Splunk alerts, Splunk reports, saved searches
- Splunk data models and role-based access controls
- Splunk SOAR
- Python
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- TCP/IP, infrastructure as code
- SOAR
Preferred
- 1+ year supporting Splunk in AWS, Microsoft Azure, or GCP
- 5+ years with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows
- 5+ years integrating Splunk with endpoint, identity, firewall, or cloud security tools
- 1+ year with Python, automation scripting, or infrastructure as code tools
- Experience supporting regulated or federal environments
Location
- Rosslyn, VA (onsite)
Compensation
- $102,500 - $188,900 USD per year
- Eligible for a discretionary annual incentive program, subject to program rules
- Incentive award, if any, depends on individual and organizational performance
Note: This role includes a travel requirement of 20% on average.
Level: Security Engineer III (Splunk Architect)
Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
Experience: 2+ years