Security Engineer III, Splunk Architect (TS Clearance)
Deloitte · Arlington, Virginia, United States · 4 wk ago
Hybrid$103k–$189k/yrFull-time
About the role
The Deloitte Cyber team specializes in helping businesses navigate cybersecurity challenges and opportunities. We offer powerful solutions and managed services to enhance operational resilience and security outcomes.
Responsibilities
- Design, implement, and optimize Splunk architectures to support security monitoring, log management, and operational analytics.
- Develop and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business requirements.
- Integrate data sources into Splunk, including infrastructure, cloud, application, and security technologies.
- Support use case development for threat detection, incident response, compliance monitoring, and operational visibility.
- Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- 2+ years of experience implementing and supporting Splunk Enterprise or Splunk Cloud.
- Experience developing Splunk dashboards, reports, alerts, and saved searches.
- Experience onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools.
- Experience with Security Information and Event Management (SIEM) concepts, security monitoring, or threat detection use cases.
- Working knowledge of Transmission Control Protocol/Internet Protocol (TCP/IP), networking protocols, and system log analysis.
- Experience with Splunk Search Processing Language (SPL), data models, and role-based access controls.
- One or more of the following certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security certification.
- Experience with Splunk in Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP).
- Experience supporting Splunk in Splunk SOAR or security orchestration workflows.
- Experience integrating Splunk with endpoint, identity, firewall, or cloud security tools.
- Experience with Python, automation scripting, or infrastructure as code tools.
- Experience supporting regulated or federal environments.
Pay
The wage range for this role is $102,500 - $188,900.