Security Engineer III, Splunk Architect
Analytics
Cloud Platforms
Cybersecurity Tools
Data Analysis
Data Platform
Data Processing
Data Security
Digital Marketing
Engineer
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Security
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Solution Architecture
Splunk
Splunk Architecture
Splunk Data Models
Splunk Siem
Splunk Soar
Job Description
Deloitte is seeking a Splunk Architect to design and optimize Splunk-based security monitoring and enterprise logging capabilities for the Cyber team.
Responsibilities
- Design, implement, and optimize Splunk architectures for security monitoring, log management, and operational analytics
- Develop and maintain Splunk dashboards, alerts, reports, searches, and data models based on client and business requirements
- Integrate data sources into Splunk, including infrastructure, cloud, applications, and security technologies
- Support use case development across threat detection, incident response, compliance monitoring, and operational visibility
- Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Ability to work onsite up to 5 days per week (Rosslyn, VA)
- 2+ years experience in one or more of the following:
- Implementing and supporting Splunk Enterprise or Splunk Cloud
- Developing Splunk dashboards, reports, alerts, and saved searches
- Onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools
- SIEM concepts, security monitoring, or threat detection use cases
- Working knowledge of TCP/IP, networking protocols, and system log analysis
- Experience with Splunk Search Processing Language (SPL), data models, and role-based access controls
- One or more certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security
- Ability to travel 20% on average based on work, clients, and industries/sectors served
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Splunk Enterprise, Splunk Cloud
- Splunk Search Processing Language (SPL)
- SIEM
- Splunk dashboards, Splunk alerts, Splunk reports, saved searches
- Splunk data models
- Role-based access controls
- Splunk SOAR
- Python
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Transmission Control Protocol/Internet Protocol (TCP/IP)
- Infrastructure as code
Preferred
- 1+ year experience supporting Splunk in AWS, Microsoft Azure, or GCP
- 5+ years experience with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows
- 5+ years experience integrating Splunk with endpoint, identity, firewall, or cloud security tools
- 1+ year experience with Python, automation scripting, or infrastructure as code tools
- Experience supporting regulated or federal environments
Compensation
- $102,500 - $188,900 per year (estimated wage range)
Incentive Program
- Eligible for a discretionary annual incentive program, subject to program rules
- Any award depends on factors including individual and organizational performance