Security Engineer III, Splunk Content Engineer
Analytics
Cybersecurity Content
Cybersecurity Tools
Data Platform
Data Processing
Data Security
Digital Marketing
Engineer
Facilities Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Security Testing
Splunk
Job Description
The Security Engineer III, Splunk Content Engineer role on Deloitte’s Government & Public Services team focuses on building and refining security information and event management content, automation, and reporting across client environments. This position supports security platforms including Splunk and others through correlation rules, schemas, and severity criteria.
Key Responsibilities
- Implement automation to optimize workflows and support consistent security response across client environments
- Develop security platform content for tools including Splunk, Archer, Tanium, Trellix, FireEye, and CrowdStrike
- Build, implement, and manage security information and event management correlation rules, logic, and content
- Tune security information and event management rules and logic to reduce false positives, known errors, and expected network behavior
- Create scheduled and ad hoc reporting, maintain event schemas, and apply customized security severity criteria
Required Qualifications
- Bachelor’s Degree or relevant experience in lieu of degree required
- Active Secret Clearance required
- Ability to work onsite in Herndon, VA up to 3 days a week
- 2+ years of experience developing, implementing, and managing security information and event management correlation rules and content
- Experience building and implementing event correlation rules, logic, and content in a security information and event management environment
- Experience tuning event correlation rules and logic to filter events tied to known network behavior, false positives, and known errors
- Experience maintaining an event schema with customized security severity criteria
- Experience creating scheduled and ad hoc reporting with security information and event management tools
- Experience with security information and event management technologies and event collector deployments in Windows and Linux operating environments
- Ability to travel 15%, on average
- Must be legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Splunk
- Archer
- Tanium
- Trellix
- FireEye
- CrowdStrike
- Security information and event management (SIEM)
- Event collectors
- Windows and Linux
Skills for Success
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
Preferred Qualifications
- Experience creating content for one or more of Splunk, Archer, Tanium, Trellix, FireEye, or CrowdStrike
- Experience supporting cyber defense, security operations, or incident response environments
- Experience working with government clients or within regulated environments
- Experience automating security workflows and operational processes
- Experience leading technical workstreams or junior team members
Location, Clearance, and Compensation
- Location: Rosslyn, VA 22209 (onsite)
- Clearance: Active Secret Clearance required
- Salary: USD 113,000 - 188,400 per year
- Wage range note: Compensation takes into account a wide range of factors used to make pay decisions
- Estimated range: $113,000-$188,400