Data Security Engineer (Tuning)
Job Description
Deloitte is hiring a Security Data Engineer (Tuning) for its Enterprise Security team in Colorado Springs, CO (onsite). This role focuses on optimizing end-to-end security telemetry pipelines and building tuned, high-fidelity detections across network, endpoint, identity, cloud, application, operational technology (OT), and security infrastructure data.
Working within Deloitte’s Government & Public Services (GPS) practice, you’ll support federal, state, and local government clients, along with public higher education institutions. The Enterprise Security offering helps embed security throughout digital transformation by securing the technical backbone while enabling secure transformation, including security architecture, secure development and deployment, and end-to-end cyber cloud capabilities.
What you’ll do
- Own end-to-end security telemetry pipelines for network traffic monitoring, threat hunting, custom detection engineering, and adversary detection, working backward from detection goals to define data sources, collection methods, telemetry fields, retention, normalization, and data-quality controls.
- Architect, build, and maintain telemetry pipelines that ingest and onboard network, endpoint, identity, cloud, application, OT, and security-infrastructure data including NetFlow, PCAP, VPC flow logs, firewall and proxy logs, and DNS records into centralized and deployed detection solutions.
- Define telemetry for key security use cases by mapping detection objectives to underlying data sources and assessing visibility gaps across on-premises, cloud, remote, and segmented environments.
- Normalize and enrich telemetry for reliable detection using OCSF or CIM standards, ensuring data is queryable and available for correlation while troubleshooting ingestion, parsing, latency, retention, field coverage, and data-quality issues across SIEM, data lake, analytics, and detection platforms.
- Design and tune detection logic using SQL, Sigma, YARA-L, or Python for network-based attack techniques such as command-and-control beaconing, data exfiltration, and lateral movement. Reduce false positives while maintaining detection signal and support custom detection development through data discovery, enrichment, normalization, and validation.
- Collaborate with network engineering and stakeholders to evaluate sensors and telemetry sources including NetFlow and IPFIX, DNS and proxy telemetry, firewall logs, IDS/IPS, packet capture, Zeek, and NDR platforms.
- Improve telemetry performance and reliability by establishing telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed data, then optimizing pipelines for performance, scalability, reliability, and cost.
Required qualifications
- Associate degree and 6+ years of experience in data engineering, data integration, security engineering, or security operations; or bachelor’s degree and 3+ years in the same areas.
- Active TS/SCI or SCI eligibility is required.
- 3+ years conducting data investigations and using scripting languages for data engineering workflows.
- Experience using SQL and Python to transform, validate, or analyze data.
- Experience using MITRE ATT&CK for security log design.
- Experience configuring or tuning data ingestion, parsing, normalization, or enrichment processes for security data.
- Experience using a SIEM platform, log management platform, or security data lake.
- Ability to travel 10% on average.
- Must be legally authorized to work in the United States without employer sponsorship.
Technologies you may work with
SQL, Python, Sigma, YARA-L, OCSF, CIM, MITRE ATT&CK, NetFlow, PCAP, VPC flow logs, DNS, IPFIX, IDS/IPS, Zeek, NDR, SIEM, CI/CD, AWS, Microsoft Azure, GCP.
Compensation (Colorado)
For individuals assigned and/or hired to work in Colorado, the estimated compensation range is $95,600 to $159,300 per year.
Recruiting timeline
Recruiting for this position will end 11/30/2026.