Security Engineer III, Splunk Architect
Job Description
Join Deloitte’s Cyber team to architect and engineer Splunk capabilities for security monitoring, enterprise logging, and operational analytics.
Responsibilities
- Design, implement, and optimize Splunk architectures for security monitoring, log management, and operational analytics
- Build and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business requirements
- Integrate log and telemetry sources into Splunk, including infrastructure, cloud, application, and security technologies
- Support development of threat detection, incident response, compliance monitoring, and operational visibility use cases
- Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days a week
- Implementing and supporting Splunk Enterprise or Splunk Cloud
- Develop Splunk dashboards, reports, alerts, and saved searches
- Onboard and normalize log sources from infrastructure, applications, cloud platforms, or security tools
- SIEM concepts with security monitoring or threat detection use case experience
- Working knowledge of TCP/IP, networking protocols, and system log analysis
- Experience with Splunk Search Processing Language (SPL), Splunk data models, and role-based access controls
- One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security
- Ability to travel 20% on average based on client needs and sectors
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Preferred
- 1+ year supporting Splunk in AWS, Microsoft Azure, or GCP
- 5+ years of Splunk Enterprise Security, Splunk SOAR, or security orchestration workflow experience
- 5+ years integrating Splunk with endpoint, identity, firewall, or cloud security tools
- 1+ year experience with Python, automation scripting, or infrastructure as code tools
- Experience supporting regulated or federal environments
Successful Candidate Skills
- Ability to work independently and collaborate in a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
Technologies
- Splunk Enterprise
- Splunk Cloud
- Splunk Search Processing Language (SPL)
- TCP/IP
- SIEM
- Splunk dashboards, Splunk alerts, Splunk reports, saved searches
- Splunk data models
- Role-based access controls
Location and Salary
- Baltimore, MD (onsite)
- USD 102,500 - 188,900 per year
Team and Offering
- Deloitte’s Deloitte Cyber team focuses on the unique challenges and opportunities businesses face in cybersecurity
- Cyber defense and resilience offering supports managing and protecting dynamic attack surfaces, enabling rapid crisis and cyber incident response for readiness, response, and recovery
Role Context
- Security Engineer III (Splunk Architect) role on Deloitte’s Cyber team
- Designs, implements, and optimizes Splunk solutions for security monitoring, visibility, and enterprise logging strategies
- Combines hands-on Splunk engineering with architecture responsibilities to support threat detection and operational resilience