EngineerJobs.io
← Back to all jobs

Job Description

Design and engineer Splunk-based security monitoring solutions in a hands-on architecture role for Deloitte’s Cyber team.

Responsibilities

  • Design, implement, and optimize Splunk architectures for security monitoring, log management, and operational analytics
  • Build and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business needs
  • Integrate data from infrastructure, cloud, applications, and security technologies into Splunk
  • Support use case development for threat detection, incident response, compliance monitoring, and operational visibility
  • Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance
  • Ability to work onsite up to 5 days a week
  • 2+ years of experience with:
    • Implementing and supporting Splunk Enterprise or Splunk Cloud
    • Developing Splunk dashboards, reports, alerts, and saved searches
    • Onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools
    • SIEM concepts, security monitoring, or threat detection use cases
    • Working knowledge of TCP/IP, networking protocols, and system log analysis
    • Splunk SPL, data models, and role-based access controls
  • One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security
  • Ability to travel 20%, on average, based on work and client/industry needs
  • Legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Splunk Enterprise, Splunk Cloud
  • Splunk Search Processing Language (SPL)
  • SIEM
  • Splunk dashboards, Splunk alerts, Splunk reports, saved searches
  • Splunk data models and role-based access controls
  • Splunk SOAR
  • Python
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • TCP/IP, infrastructure as code
  • SOAR

Preferred

  • 1+ year supporting Splunk in AWS, Microsoft Azure, or GCP
  • 5+ years with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows
  • 5+ years integrating Splunk with endpoint, identity, firewall, or cloud security tools
  • 1+ year with Python, automation scripting, or infrastructure as code tools
  • Experience supporting regulated or federal environments

Location

  • Rosslyn, VA (onsite)

Compensation

  • $102,500 - $188,900 USD per year
  • Eligible for a discretionary annual incentive program, subject to program rules
  • Incentive award, if any, depends on individual and organizational performance

Note: This role includes a travel requirement of 20% on average.

Level: Security Engineer III (Splunk Architect)

Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field

Experience: 2+ years

Similar Jobs