EngineerJobs.io
← Back to all jobs

Job Description

Deloitte’s Government & Public Services team is seeking a Security Engineer III to support security information and event management (SIEM) content engineering across client environments. This role focuses on building and tuning SIEM content, automation, and reporting, with support for platforms including Splunk and others.

Working onsite in the Rosslyn, VA area, the engineer will develop correlation rules, schemas, and severity criteria, and will tune detection logic to improve signal quality and response consistency.

Role Summary

The Security Engineer III will build and maintain SIEM correlation logic and content, including automations and reporting workflows. The position supports security platforms such as Splunk and other listed tools by implementing correlation rules, schemas, and severity criteria to align with client needs.

Responsibilities

  • Implement automation to optimize workflows and improve security response uniformity across client environments
  • Develop SIEM and security platform content for Splunk, Archer, Tanium, Trellix, FireEye, and CrowdStrike
  • Build, implement, and manage SIEM correlation rules, logic, and content
  • Tune SIEM correlation rules and logic to reduce false positives, known errors, and expected network behavior
  • Create scheduled and ad hoc reporting, maintain event schemas, and apply customized security severity criteria

Required Qualifications

  • Bachelor’s Degree or relevant experience in lieu of degree required
  • Active Secret Clearance required
  • Ability to work onsite in Herndon, VA up to 3 days a week
  • 2+ years of experience with SIEM correlation content, including:
    • Developing, implementing, and managing SIEM correlation rules and content
    • Building and implementing event correlation rules, logic, and content in a SIEM environment
    • Tuning correlation rules and logic to filter events tied to known network behavior, false positives, and known errors
    • Maintaining an event schema with customized security severity criteria
    • Creating scheduled and ad hoc reporting with SIEM tools
    • Using security information and event management technologies and event collector deployments in Windows and Linux environments
  • Ability to travel 15% on average
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Splunk, Archer, Tanium, Trellix, FireEye, CrowdStrike
  • Security information and event management, event collectors
  • Windows, Linux

Additional Skills

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

Preferred Qualifications

  • Experience creating content for one or more of: Splunk, Archer, Tanium, Trellix, FireEye, CrowdStrike
  • Experience supporting cyber defense, security operations, or incident response environments
  • Experience working with government clients or within regulated environments
  • Experience automating security workflows and operational processes
  • Experience leading technical workstreams or junior team members

Location and Compensation

  • Location: Rosslyn, VA 22209 (onsite)
  • Pay range: USD 113,000 - 188,400 per yearly

Similar Jobs