Security Engineer Iii, Splunk Content Engineer (secret Clearance)

Security Engineer III, Splunk Content Engineer role at Deloitte focuses on developing and implementing content for security platforms like Splunk, Archer, Tanium, Trellix, FireEye, and CrowdStrike. Responsibilities include building correlation rules, tuning security information and event management (SIEM) rules to reduce false positives, and creating reports. The role emphasizes automation to optimize workflows and improve security response uniformity. Requires an active Secret Clearance and experience with security platforms and automation in security operations.

What you'd actually do

  1. Implementing automation to optimize workflows and improve security response uniformity across client environments
  2. Developing content for security platforms such as Splunk, Archer, Tanium, Trellix, FireEye, and CrowdStrike
  3. Building, implementing, and managing security information and event management correlation rules, logic, and content
  4. Tuning security information and event management rules and logic to reduce false positives, known errors, and expected network behavior
  5. Creating scheduled and ad hoc reporting, maintaining event schemas, and applying customized security severity criteria

Skills

Required

  • Bachelor's Degree
  • Active Secret Clearance
  • Experience creating content for security platforms (Splunk, Archer, Tanium, Trellix, FireEye, CrowdStrike)
  • Experience automating security workflows and operational processes
  • Experience supporting cyber defense, security operations, or incident response environments

Nice to have

  • Experience working with government clients or within regulated environments
  • Experience leading technical workstreams or junior team members

What the JD emphasized

  • Active Secret Clearance required
  • Ability to work onsite in Herndon, VA up to 3 days a week