Security Engineer III, Splunk Architect (TS Clearance)
- Deloitte
- Arlington, Virginia
- Full Time
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Splunk plays a critical role in helping organizations monitor, detect, investigate, and respond to cyber threats across complex environments. As a Splunk Engineer/Architect, you will design, implement, and optimize Splunk solutions that support security operations, visibility, and enterprise logging strategies. This role combines hands-on engineering with architecture responsibilities to help clients improve operational resilience and security outcomes.
Work you'll do
As a Splunk Architect on the Cyber team, you will be responsible for:
Design, implement, and optimize Splunk architectures to support security monitoring, log management, and operational analytics.
Develop and maintain Splunk dashboards, alerts, reports, searches, and data models aligned to client and business requirements.
Integrate data sources into Splunk, including infrastructure, cloud, application, and security technologies.
Support use case development for threat detection, incident response, compliance monitoring, and operational visibility.
Create and maintain architecture diagrams, technical documentation, implementation standards, and administration procedures.
A successful candidate would possess these skills:
Ability to work independently and collaborate as part of a team
Effective written and verbal communication skills
Meticulous attention to detail and quality of work product
Ability to build and sustain professional relationships
Ability to lead projects or workstreams
Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
Strong interpersonal skills and professional demeanor
Ability to meet deadlines
Ability to provide clear guidance to others
The team
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
Qualifications
Required:
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
Active Top-Secret Clearance.
Ability to work onsite up to 5 days a week.
2+ years of experience within the following:
Implementing and supporting Splunk Enterprise or Splunk Cloud
Developing Splunk dashboards, reports, alerts, and saved searches
Onboarding and normalizing log sources from infrastructure, applications, cloud platforms, or security tools
Security Information and Event Management (SIEM) concepts, security monitoring, or threat detection use cases
Working knowledge of Transmission Control Protocol/Internet Protocol (TCP/IP), networking protocols, and system log analysis
Experience with Splunk Search Processing Language (SPL), data models, and role-based access controls
Must have one or more of the certifications: Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security certification
Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
1+ year of experience supporting Splunk in Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP)
5+ years of experience with Splunk Enterprise Security, Splunk SOAR, or security orchestration workflows
5+ years of experience integrating Splunk with endpoint, identity, firewall, or cloud security tools
1+ year of experience with Python, automation scripting, or infrastructure as code tools
Experience supporting regulated or federal environments
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $102,500- $188,900.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.