CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte Cyber Defense and Resilience is seeking a SIEM Engineer to strengthen security monitoring and detection engineering across complex enterprise environments. The role supports incident analysis and improves alert fidelity through well-tuned SIEM content and reliable log integration.

Responsibilities

  • Configure, maintain, and optimize SIEM content, including correlation rules, alerts, dashboards, and reports
  • Analyze security events and log data to identify suspicious activity, support investigations, and expand detection coverage
  • Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
  • Partner with cybersecurity teams to support use case development, threat detection, incident triage, and response activities
  • Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery

Required Qualifications

  • Bachelor's degree in computer science, cybersecurity, information technology, engineering, or a related technical field
  • Active Secret Clearance
  • 3+ years of experience in cybersecurity, security operations, or SIEM engineering
  • 3+ years of experience with at least one of the following: Splunk, Palo Alto XSIAM, or CrowdStrike NG SIEM
  • 2+ years experience in:
    • Creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a Security Information and Event Management platform
    • Reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
  • Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required
  • Ability to travel up to 20%, on average
  • Willingness to work at client onsite or Deloitte office up to 5 days a week
  • Legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Splunk
  • Palo Alto XSIAM
  • CrowdStrike NG SIEM
  • Splunk certification
  • Palo Alto Networks certification
  • CrowdStrike certification
  • Security Information and Event Management platform
  • MITRE ATT&CK

Work Setting

Location is Rosslyn, VA (remote). Travel up to 20% on average may be required, along with potential client onsite or Deloitte office work up to 5 days per week.

Additional Skills

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

Preferred Qualifications

  • 2+ years experience:
    • Supporting enterprise monitoring in a Security Operations Center
    • Onboarding and normalizing log sources in a Security Information and Event Management platform
    • Mapping detections to MITRE ATT&CK techniques
    • Cloud security monitoring in Amazon Web Services, Microsoft Azure, or Google Cloud Platform
    • Hands-on experience with scripting or query languages used for detection and log analysis
  • Security certification such as CompTIA Security+ or GIAC certification

Compensation and Incentives

The salary range for this role is USD 102,500 - 188,900 per year. Deloitte may also offer eligibility to participate in a discretionary annual incentive program, subject to program rules and factors including individual and organizational performance.

Education

A Bachelor's degree in computer science, cybersecurity, information technology, engineering, or a related technical field is required.

Similar Jobs