Security Engineer III, Splunk Architect
Job Description
Deloitte is seeking a Security Engineer III, Splunk Architect to design, implement, and optimize Splunk solutions for security monitoring, visibility, and enterprise logging strategies. The position blends hands-on engineering with architecture responsibilities to support threat detection, incident response, and compliance monitoring within a cybersecurity-focused team.
Responsibilities
- Design, implement, and optimize Splunk architectures to enable security monitoring, log management, and operational analytics.
- Develop and maintain Splunk dashboards, alerts, reports, searches, and data models based on client and business requirements.
- Integrate data sources into Splunk, including infrastructure, cloud, application, and security technologies.
- Support development of security use cases spanning threat detection, incident response, compliance monitoring, and operational visibility.
- Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
- Active Top-Secret Clearance.
- Ability to work onsite up to 5 days a week.
- 2+ years of experience implementing and supporting Splunk Enterprise or Splunk Cloud.
- 2+ years of experience developing Splunk dashboards, reports, alerts, and saved searches.
- Experience onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools.
- Understanding of SIEM concepts, security monitoring, or threat detection use cases.
- Working knowledge of TCP/IP, networking protocols, and system log analysis.
- Experience with Splunk Search Processing Language (SPL), Splunk data models, and role-based access controls.
- One or more of the following certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security.
- Ability to travel 20% on average based on client needs and sectors.
- Legal authorization to work in the United States without employer sponsorship, now or in the future.
Technologies
- Splunk Enterprise, Splunk Cloud
- Splunk Search Processing Language (SPL)
- Splunk dashboards, Splunk data models
- Transmission Control Protocol/Internet Protocol (TCP/IP)
- SIEM
- Python
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Splunk Enterprise Security, Splunk SOAR
Preferred
- 1+ year of experience supporting Splunk in AWS, Microsoft Azure, or GCP.
- 5+ years of experience with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows.
- 5+ years of experience integrating Splunk with endpoint, identity, firewall, or cloud security tools.
- 1+ year of experience with Python, automation scripting, or infrastructure as code tools.
- Experience supporting regulated or federal environments.
Skills for Success
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines and provide clear guidance to others.
Team
- Deloitte’s Cyber team supports businesses with the unique challenges and opportunities in cybersecurity.
- Cyber Defense & Resilience helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence.
- The offering helps manage and protect dynamic attack surfaces and supports rapid crisis and cyber incident response, enabling clients to be ready for, respond to, and recover from business disruptions.
Location and Pay
Arlington, VA (onsite). Salary range: USD 102,500 - 188,900 per year. Minimum experience: 2 years.