Data Security Engineer (Tuning)
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.
Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape.
Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Recruiting for this position will end 11/30/2026.
Work You'll Do
As a Security Data Engineer (Tuning) - Cyber/ Enterprise Security on the Enterprise Security team, you will be responsible for..
* Owning end-to-end security telemetry pipelines that support network traffic monitoring, threat hunting, custom detection engineering, and adversary detection.
You will work backward from detection objectives to establish the data sources, collection methods, telemetry fields, retention, normalization, and data-quality controls needed for reliable detection coverage.
* Architect, build, and maintain security telemetry pipelines that identify, onboard, and ingest network, endpoint, identity, cloud, application, operational technology (OT), and security-infrastructure data-including NetFlow, packet capture (PCAP), virtual private cloud (VPC) flow logs, firewall and proxy logs, and Domain Name System (DNS) records-into centralized and deployed detection solutions.
* Determine telemetry needed for network monitoring, threat hunting, incident response, and custom detection engineering; map detection objectives to underlying data sources; and assess visibility gaps across on-premises, cloud, remote, and segmented environments.
* Normalize, enrich, parse, validate, and maintain telemetry using Open Cybersecurity Schema Framework (OCSF) or Common Information Model (CIM) standards; ensure data is queryable and available for correlation; and troubleshoot ingestion, parsing, latency, retention, field-coverage, and data-quality issues across security information and event management (SIEM), data lake, analytics, and detection platforms.
* Design, write, deploy, and tune high-fidelity detection logic using Structured Query Language (SQL), Sigma, YARA-L, or Python for network-based attack techniques, including command-and-control beaconing, data exfiltration, and lateral movement; reduce false positives while maintaining detection signal; and support custom detection development through data discovery, enrichment, normalization, validation, and behavioral and tradecraft-based detection.
* Partner with network engineering and organizational stakeholders to evaluate network sensors, NetFlow and Internet Protocol Flow Information Export (IPFIX), DNS and proxy telemetry, firewall logs, intrusion detection and prevention systems (IDS/IPS), packet capture, Zeek or network metadata, and network detection and response (NDR) platforms.
* Establish telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed ...
- Rate: Not Specified
- Location: Colorado Springs, US-CO
- Type: Permanent
- Industry: Management
- Recruiter: Deloitte
- Contact: Not Specified
- Email: to view click here
- Reference: 370689
- Posted: 2026-10-10 09:59:41 -
- View all Jobs from Deloitte
More Jobs from Deloitte
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director
- Defence Account Director