CybersecurityJobs.io
← Back to all jobs

Job Description

Deloitte is seeking a Splunk Architect to design and optimize Splunk-based security monitoring and enterprise logging capabilities for the Cyber team.

Responsibilities

  • Design, implement, and optimize Splunk architectures for security monitoring, log management, and operational analytics
  • Develop and maintain Splunk dashboards, alerts, reports, searches, and data models based on client and business requirements
  • Integrate data sources into Splunk, including infrastructure, cloud, applications, and security technologies
  • Support use case development across threat detection, incident response, compliance monitoring, and operational visibility
  • Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
  • Active Top-Secret Clearance
  • Ability to work onsite up to 5 days per week (Rosslyn, VA)
  • 2+ years experience in one or more of the following:
    • Implementing and supporting Splunk Enterprise or Splunk Cloud
    • Developing Splunk dashboards, reports, alerts, and saved searches
    • Onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools
    • SIEM concepts, security monitoring, or threat detection use cases
    • Working knowledge of TCP/IP, networking protocols, and system log analysis
    • Experience with Splunk Search Processing Language (SPL), data models, and role-based access controls
  • One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security
  • Ability to travel 20% on average based on work, clients, and industries/sectors served
  • Legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Splunk Enterprise, Splunk Cloud
  • Splunk Search Processing Language (SPL)
  • SIEM
  • Splunk dashboards, Splunk alerts, Splunk reports, saved searches
  • Splunk data models
  • Role-based access controls
  • Splunk SOAR
  • Python
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • Transmission Control Protocol/Internet Protocol (TCP/IP)
  • Infrastructure as code

Preferred

  • 1+ year experience supporting Splunk in AWS, Microsoft Azure, or GCP
  • 5+ years experience with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows
  • 5+ years experience integrating Splunk with endpoint, identity, firewall, or cloud security tools
  • 1+ year experience with Python, automation scripting, or infrastructure as code tools
  • Experience supporting regulated or federal environments

Compensation

  • $102,500 - $188,900 per year (estimated wage range)

Incentive Program

  • Eligible for a discretionary annual incentive program, subject to program rules
  • Any award depends on factors including individual and organizational performance

Similar Jobs