Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance)

PowerToFly

Virginia (IL)

On-site

USD 138,000 - 230,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Discretionary annual incentive program

Job summary

Deloitte's Government & Public Services (GPS) Cyber Defense & Resilience team seeks a SOC professional to design and optimize Splunk dashboards, develop advanced reporting, and mentor junior analysts. Onsite in Herndon, VA with travel up to 15%. Requires Active Secret Clearance and 3+ years in SIEM.

Join a team delivering security operations, data analytics, and threat intelligence to government clients and public institutions.

Qualifications

  • Bachelor's Degree required.
  • Active Secret Clearance required.
  • Ability to work onsite in Herndon, VA up to 3 days a week.
  • 3+ years of experience in designing/configuring SIEM dashboards, reports, alerts, and SOPs.
  • Experience mentoring junior and mid-level analysts.
  • Experience with enterprise logging solutions and regex.

Responsibilities

  • Design, customize, configure, and optimize Splunk dashboards, apps, alerts, and visualizations.
  • Develop advanced reporting and visualizations to support SOC operations.
  • Build, test, document, implement, and tune security content across the full lifecycle.
  • Perform advanced searches and analysis in large-scale SIEM environments.
  • Mentor junior and mid-level analysts on SOC processes and content development.
  • Travel up to 15% based on client needs.

Skills

Team collaboration
Communication
Attention to detail
Relationship building
Project leadership
Task prioritization
Interpersonal skills
Deadline oriented
Mentoring

Education

Bachelor's degree

Tools

Splunk

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work you'll do
  • Design, customize, configure, and optimize Splunk dashboards, applications, alerts, and visualizations to improve SOC performance and maturity.
  • Develop advanced reporting and visualizations to support SOC operations and stakeholder requirements.
  • Build, test, document, implement, and tune security content across the full lifecycle, including data models, dashboards, correlation logic, searches, and alert notifications.
  • Perform advanced searches and analysis in large-scale SIEM environments.
  • Analyze, trend, and filter security log data from multiple sources, including firewalls, IDS/IPS, hosts, load balancers, and other security and monitoring tools.
  • Develop and enhance custom SPL using macros, lookups, regex, and network-based logic.
  • Support SOP development, updates, implementation, and training.
  • Mentor junior and mid-level analysts on SOC processes, content development, and detection practices.
  • Identify and use indicators of compromise (IOCs) and network traffic indicators to detect anomalous activity, including lateral movement.
  • Support enterprise logging use cases across application, operating system, and security device logs.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others
The team

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.

Qualifications

Required:

  • Bachelor's Degree required.
  • Active Secret Clearance required.
  • Ability to work onsite in Herndon, VA up to 3 days a week.
  • 3+ years of experience within the following:
    • Extensive experience designing and configuring SIEM applications, dashboards, and visualizations for medium-to-large SOC environments.
    • Extensive experience developing advanced reporting, searches, alerts, and dashboards in Splunk or similar enterprise SIEM platforms.
    • Extensive experience analyzing high volumes of security log data from diverse enterprise security technologies.
    • Experience optimizing SIEM security content and implementing SOC processes and SOPs.
    • Experience mentoring junior and mid-level analysts.
    • Experience with enterprise logging solutions, regex, custom log parsing, and network security tools.
  • Ability to travel 15%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Candidate must possess one of the following certifications: CISSP, GCIH, GCFA, GPEN, GWAPT, GCIA, or equivalent.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $137,700 to $229,500.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer III, Splunk Content Engineer (Secret Clearance)
Security Engineer III, Splunk Content Engineer (Secret Clearance)

Relha LLC • Virginia (IL), Northern (KY)

Hybrid
USD 113,000 - 188,000
Discretionary annual incentive
Security Engineer III, Splunk Content Engineer (Secret Clearance)
Security Engineer III, Splunk Content Engineer (Secret Clearance)

Relha LLC • Herndon (VA)

Hybrid
USD 113,000 - 188,000
SEIM Engineer, Security Engineer II
SEIM Engineer, Security Engineer II

Relha LLC • Washington, Northern (KY)

Hybrid
USD 89,000 - 163,000
Cyber Supply Chain & Industrial Control Subject Matter Expert I
Cyber Supply Chain & Industrial Control Subject Matter Expert I

PowerToFly • Virginia (IL)

On-site
USD 131,000 - 218,000
Splunk Engineer
Splunk Engineer

Peraton • Herndon (VA)

On-site
USD 112,000 - 179,000
Heavily subsidized benefits coverage
25 days PTO accrued annually
Attractive bonus plan
ISSO, Senior Consultant
ISSO, Senior Consultant

PowerToFly • United States

On-site
USD 108,000 - 180,000
Senior Splunk SIEM Engineer & SOC Lead
Senior Splunk SIEM Engineer & SOC Lead

PowerToFly • Virginia (IL)

On-site
USD 138,000 - 230,000
Discretionary annual incentive program
Splunk Engineer
Splunk Engineer

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
TS/SCI Splunk Engineer — Mission-Critical Analytics
TS/SCI Splunk Engineer — Mission-Critical Analytics

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Security Analyst
Security Analyst

Relha LLC • Herndon (VA)

Hybrid
USD 113,000 - 188,000