Security Engineer III, SIEM Engineer
Job Description
Deloitte Cyber Defense and Resilience is seeking a SIEM Engineer to strengthen security monitoring and detection engineering across complex enterprise environments. The role supports incident analysis and improves alert fidelity through well-tuned SIEM content and reliable log integration.
Responsibilities
- Configure, maintain, and optimize SIEM content, including correlation rules, alerts, dashboards, and reports
- Analyze security events and log data to identify suspicious activity, support investigations, and expand detection coverage
- Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
- Partner with cybersecurity teams to support use case development, threat detection, incident triage, and response activities
- Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery
Required Qualifications
- Bachelor's degree in computer science, cybersecurity, information technology, engineering, or a related technical field
- Active Secret Clearance
- 3+ years of experience in cybersecurity, security operations, or SIEM engineering
- 3+ years of experience with at least one of the following: Splunk, Palo Alto XSIAM, or CrowdStrike NG SIEM
- 2+ years experience in:
- Creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a Security Information and Event Management platform
- Reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
- Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required
- Ability to travel up to 20%, on average
- Willingness to work at client onsite or Deloitte office up to 5 days a week
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Splunk
- Palo Alto XSIAM
- CrowdStrike NG SIEM
- Splunk certification
- Palo Alto Networks certification
- CrowdStrike certification
- Security Information and Event Management platform
- MITRE ATT&CK
Work Setting
Location is Rosslyn, VA (remote). Travel up to 20% on average may be required, along with potential client onsite or Deloitte office work up to 5 days per week.
Additional Skills
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
Preferred Qualifications
- 2+ years experience:
- Supporting enterprise monitoring in a Security Operations Center
- Onboarding and normalizing log sources in a Security Information and Event Management platform
- Mapping detections to MITRE ATT&CK techniques
- Cloud security monitoring in Amazon Web Services, Microsoft Azure, or Google Cloud Platform
- Hands-on experience with scripting or query languages used for detection and log analysis
- Security certification such as CompTIA Security+ or GIAC certification
Compensation and Incentives
The salary range for this role is USD 102,500 - 188,900 per year. Deloitte may also offer eligibility to participate in a discretionary annual incentive program, subject to program rules and factors including individual and organizational performance.
Education
A Bachelor's degree in computer science, cybersecurity, information technology, engineering, or a related technical field is required.