CybersecurityJobs.io
← Back to all jobs

Job Description

The Security Engineer III, Splunk Content Engineer role on Deloitte’s Government & Public Services team focuses on building and refining security information and event management content, automation, and reporting across client environments. This position supports security platforms including Splunk and others through correlation rules, schemas, and severity criteria.

Key Responsibilities

  • Implement automation to optimize workflows and support consistent security response across client environments
  • Develop security platform content for tools including Splunk, Archer, Tanium, Trellix, FireEye, and CrowdStrike
  • Build, implement, and manage security information and event management correlation rules, logic, and content
  • Tune security information and event management rules and logic to reduce false positives, known errors, and expected network behavior
  • Create scheduled and ad hoc reporting, maintain event schemas, and apply customized security severity criteria

Required Qualifications

  • Bachelor’s Degree or relevant experience in lieu of degree required
  • Active Secret Clearance required
  • Ability to work onsite in Herndon, VA up to 3 days a week
  • 2+ years of experience developing, implementing, and managing security information and event management correlation rules and content
  • Experience building and implementing event correlation rules, logic, and content in a security information and event management environment
  • Experience tuning event correlation rules and logic to filter events tied to known network behavior, false positives, and known errors
  • Experience maintaining an event schema with customized security severity criteria
  • Experience creating scheduled and ad hoc reporting with security information and event management tools
  • Experience with security information and event management technologies and event collector deployments in Windows and Linux operating environments
  • Ability to travel 15%, on average
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future

Technologies

  • Splunk
  • Archer
  • Tanium
  • Trellix
  • FireEye
  • CrowdStrike
  • Security information and event management (SIEM)
  • Event collectors
  • Windows and Linux

Skills for Success

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

Preferred Qualifications

  • Experience creating content for one or more of Splunk, Archer, Tanium, Trellix, FireEye, or CrowdStrike
  • Experience supporting cyber defense, security operations, or incident response environments
  • Experience working with government clients or within regulated environments
  • Experience automating security workflows and operational processes
  • Experience leading technical workstreams or junior team members

Location, Clearance, and Compensation

  • Location: Rosslyn, VA 22209 (onsite)
  • Clearance: Active Secret Clearance required
  • Salary: USD 113,000 - 188,400 per year
  • Wage range note: Compensation takes into account a wide range of factors used to make pay decisions
  • Estimated range: $113,000-$188,400

Similar Jobs