Data Security Engineer (Tuning)

Deloitte France

Colorado Springs (CO)

On-site

USD 96,000 - 159,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Deloitte is seeking a cybersecurity data engineer to own and optimize security telemetry pipelines across network, cloud, and OT data sources. You will design, implement, and tune detection logic and data enrichment processes to support SIEM and analytics platforms.

The role requires TS/SCI eligibility and the ability to collaborate with network engineers and stakeholders in a fast-paced environment. Colorado compensation reflects local market ranges and incentive opportunities.

Qualifications

  • Associate degree with 6+ years in data engineering, data integration, security engineering or security operations, or a bachelor’s degree with 3+ years in these areas.
  • Active TS/SCI or SCI eligibility is required.
  • 3+ years of data investigations and scripting for data engineering workflows.

Responsibilities

  • Own end-to-end security telemetry pipelines supporting network monitoring, threat hunting, and detection engineering.
  • Architect, build, and maintain telemetry pipelines ingesting network, endpoint, identity, cloud, and OT data into detection solutions.
  • Map detection objectives to data sources and assess visibility gaps across on-prem, cloud, and remote environments.
  • Normalize, enrich, parse, validate telemetry using OC SF or CIM standards; ensure data is queryable for SIEM, data lake, analytics, and detection platforms.
  • Design and tune high-fidelity detection logic using SQL, Sigma, YARA-L, or Python for network-based attacks.
  • Collaborate with network engineering and stakeholders to evaluate sensors, NetFlow/IPFIX, DNS, firewall logs, and NDR platforms.
  • Establish telemetry health metrics, dashboards, and automated checks; optimize ingestion pipelines for performance and cost.

Skills

Independent work
Team collaboration
Communication skills
Attention to detail
Relationship building
Project leadership
Task prioritization
Deadline oriented
Guidance to others

Education

Associate degree
Bachelor’s degree

Tools

SQL
Python

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this position will end 11/30/2026.

Work You’ll Do
  • Owning end-to-end security telemetry pipelines that support network traffic monitoring, threat hunting, custom detection engineering, and adversary detection. You will work backward from detection objectives to establish the data sources, collection methods, telemetry fields, retention, normalization, and data-quality controls needed for reliable detection coverage.
  • Architect, build, and maintain security telemetry pipelines that identify, onboard, and ingest network, endpoint, identity, cloud, application, operational technology (OT), and security‑infrastructure data—including NetFlow, packet capture (PCAP), virtual private cloud (VPC) flow logs, firewall and proxy logs, and Domain Name System (DNS) records—into centralized and deployed detection solutions.
  • Determine telemetry needed for network monitoring, threat hunting, incident response, and custom detection engineering; map detection objectives to underlying data sources; and assess visibility gaps across on‑premises, cloud, remote, and segmented environments.
  • Normalize, enrich, parse, validate, and maintain telemetry using Open Cybersecurity Schema Framework (OCSF) or Common Information Model (CIM) standards; ensure data is queryable and available for correlation; and troubleshoot ingestion, parsing, latency, retention, field‑coverage, and data‑quality issues across security information and event management (SIEM), data lake, analytics, and detection platforms.
  • Design, write, deploy, and tune high‑fidelity detection logic using Structured Query Language (SQL), Sigma, YARA‑L, or Python for network‑based attack techniques, including command-and‑control beaconing, data exfiltration, and lateral movement; reduce false positives while maintaining detection signal; and support custom detection development through data discovery, enrichment, normalization, validation, and behavioral and tradecraft‑based detection.
  • Partner with network engineering and organizational stakeholders to evaluate network sensors, NetFlow and Internet Protocol Flow Information Export (IPFIX), DNS and proxy telemetry, firewall logs, intrusion detection and prevention systems (IDS/IPS), packet capture, Zeek or network metadata, and network detection and response (NDR) platforms.
  • Establish telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed data; assess visibility across environments; and optimize telemetry architectures and ingestion pipelines for performance, scalability, reliability, and cost.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast‑paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others
The Team

Deloitte’s Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client’s technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery‑focused professionals.

Qualifications

Required:

  • Associate degree and 6+ years of experience in data engineering, data integration, security engineering, or security operations; or bachelor’s degree and 3+ years of experience in data engineering, data integration, security engineering, or security operations
  • An Active TS/SCI or SCI eligibility is required
  • 3+ years of experience conducting data investigations and using scripting languages for data engineering workflows.
  • + years of experience using Structured Query Language (SQL) and Python to transform, validate, or analyze data
  • Experience using MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) for security log design
  • Experience configuring or tuning data ingestion, parsing, normalization, or enrichment processes for security data
  • Experience using a security information and event management (SIEM) platform, log management platform, or security data lake
  • Ability to travel 10%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Cyber threat hunting
  • Experience with cloud data or security services in Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP)
  • Experience using version-control and continuous integration/continuous delivery (CI/CD) tooling to deploy engineering changes

For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Colorado and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $95,600 to $159,300.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

ReferencesVisible links1. https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • Las Vegas (NV)

On-site
USD 83,000 - 163,000
Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • Tampa (FL)

On-site
USD 83,000 - 163,000
Cyber Operate Detection Engineer - Consultant
Cyber Operate Detection Engineer - Consultant

Deloitte France • Miami (FL)

On-site
USD 83,000 - 163,000
Senior Consultant Cyber Engineering
Senior Consultant Cyber Engineering

Deloitte France • Miami (FL)

On-site
USD 98,000 - 201,000
Senior Consultant Cyber Engineering
Senior Consultant Cyber Engineering

Deloitte France • Tempe (AZ)

On-site
USD 98,000 - 201,000
Senior Consultant Cyber Engineering
Senior Consultant Cyber Engineering

Deloitte France • Boise (ID)

On-site
USD 98,000 - 201,000
Senior Consultant Cyber Engineering
Senior Consultant Cyber Engineering

Deloitte France • Tampa (FL)

On-site
USD 98,000 - 201,000
Senior Consultant Cyber Engineering
Senior Consultant Cyber Engineering

Deloitte France • Las Vegas (NV)

On-site
USD 98,000 - 201,000
Cyber Identity - FDE Senior Consultant - Senior Engineering Management Specialist
Cyber Identity - FDE Senior Consultant - Senior Engineering Management Specialist

Deloitte France • Miami (FL)

On-site
USD 135,000 - 265,000
Defense Cyber Operations Engineer, Senior Consultant
Defense Cyber Operations Engineer, Senior Consultant

Deloitte France • Colorado Springs (CO)

On-site
USD 120,000 - 170,000