Global Cyber Defense Splunk Engineer – Infrastructure

Cyber Security Cyber Risk Posted: 27-Apr-2022

Same job available in 8 locations

Alexandria, Virginia, United States

Arlington, Virginia, United States

Baltimore, Maryland, United States

Mclean, Virginia, United States

Richmond, Virginia, United States

Rosslyn, Virginia, United States

Toronto, Ontario, Canada

Washington Dc, Virginia, United States

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

Work you'll do

The successful candidate will provide ongoing engineering of the current Splunk infrastructure as well as the migration/implementation of Splunk products in a global multi-data center environment. This role also requires a forward-thinking consultative approach and a high degree of collaboration with the Splunk architect and customer Infrastructure teams.

The GEMS Senior Engineer works closely with team leadership to ensure integration of operations and maintenance to team standards. He/she will have experience in log source onboarding, and maintenance of Splunk and Splunk ES. He/she exhibits a high service attitude and operations discipline to deliver a 24x7, highly available and highly performing, production application.

  • Partner with development and operations teams to develop practical automation solutions and custom modules.
  • Co-lead team initiatives to continuously refine our deployment practices for improved reliability, repeatability, and security. Creating plans and collaborating with other GEMS Engineering team members, while coordinating with development and business teams.
  • Develop requirements for data ingestion methods based on input from stakeholders/leadership.
  • Clearly document and diagram deployment-specific aspects of architectures and environments, working closely with various teams to create application runbooks, playbooks, and knowledge base documents.
  • Troubleshoot issues in production and other environments, applying debugging and problem-solving techniques (e.g., log analysis, non-invasive tests).
  • Suggest deployment patterns & practices improvements based on learnings from past deployments and production issues, collaborate with GEMS Engineering team members to implement these.
  • After hours on-call support occasionally required.

The team

The Deloitte Global Cybersecurity function is responsible for enhancing data protection, standardizing and securing critical infrastructure, and gaining cyber visibility through security operations centers. The Cybersecurity organization delivers a comprehensive set of security services to Deloitte’s global network of firms around the globe.


  • 2+ years Splunk engineering experience
  • 1+ years managing other Splunk engineers or projects
  • Strong understanding of Cloud Services – Azure, AWS
  • Strong understanding of Splunk data onboarding including Splunk App/TA configuration and CIM validation
  • Universal/Heavy Forwarder configuration experience, including encryption and compression settings
  • Experience working with a strict change control process utilizing tools such as Azure DevOps
  • Management/deployment experience with large scale/distributed Splunk environments
  • A solid understanding of Windows and Linux administration utilizing Command Line Interface (CLI)
  • Knowledge of networking, firewalls, load balancers etc.
  • Demonstrate understanding of common enterprise applications (especially in the area of security)
  • Knowledge of best practices for IT operations in an always-on, always-available service model
  • Excellent communication skills and the ability to communicate appropriately with/manage technical teams
  • Excellent influencing and reasoning skills; good at conflict resolution and consensus building
  • Ability to quickly explore, examine and understand complex problems
Education and experience:
  • Bachelor’s degree in Computer Science, Computer Engineering, Finance, Mathematics, Business Information Systems or other bachelor’s degree combined with relevant experience and accomplishments.
  • One or more of the following: Splunk Certified Admin, Splunk Certified Architect, Splunk Certified Consultant
  • Experience with Cribl administration and data onboarding
  • Experience in working in a large global organization

Our culture

At Deloitte Global people are valued and respected for who they are – with opportunities to bring their unique perspectives, talents and passions to business challenges. Our global workspace creates room for individuality and collaboration. Ours is an inclusive, supportive, connected culture with a focus on development, flexibility, and well-being. This culture makes Deloitte Global one of the most rewarding places to work, and to transform your career.

Professional development

From entry-level employees to senior leaders, we believe in investing in you, helping you identify and hone your unique strengths at every step of your career. We offer opportunities to build new skills, take on leadership opportunities, and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.


At Deloitte, we value our people and offer employees a broad range of benefits. Our Total Rewards program reflects our continued commitment to lead from the front in everything we do—that’s why we take pride in offering a comprehensive variety of programs and resources to support your health and well-being.

At Deloitte Global, we know we’re at our best when we look out for one another; prioritize respect, fairness, development and wellbeing; foster an inclusive culture and embrace diversity in all forms. All qualified applicants will receive consideration for employment regardless of their background, experience, identity, ability or thinking style, and if you need assistance or an accommodation during the application process for accessibility reasons this is available upon request. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.