Denver, CO

Salary
$105,400–$207,800from the description
Posted
Jul 29, 2026
Location
Denver, CO
Last confirmed open
Jul 29, 2026

What this job asks for AI summary

A client-facing security engineering consultant role at Deloitte focused on designing and implementing security operations capabilities — SIEM, SOAR, detection engineering, telemetry pipelines, and AI-assisted workflows — for enterprise clients. The role involves building integrations and automation playbooks, tuning detection content, and translating operational requirements into production-ready solutions, with roughly 50% travel to client sites.

Senior level · 6+ years · Full-time

Must have (4)
SIEMSOARPython or Scripting Languagessecurity telemetry
Nice to have (8)
AWS, Azure or GCPXDRthreat intelligencethreat huntingdata pipelinesLLMsmachine learningSplunk

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
SIEM55%Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.

Why we read it this way (8)

No specific work location is stated in the posting; the role requires ~50% travel to client sites but appears to be US-based with no fixed office requirement.

The degree requirement lists a Bachelor's in a relevant field 'or equivalent work experience,' so it is treated as not a hard degree gate.

The SOC classification is a close call: the role is primarily security-focused (SIEM/SOAR/detection engineering) which points to 15-1212, but a significant portion of the day-to-day work involves building integrations, automation playbooks, and data pipelines in Python, which overlaps with 15-1252 Software Developers. 15-1212 was chosen because the security analysis and operations mission is the primary framing.

Python is listed under Required with 'or a similar scripting language'; it is treated as a hard gate on scripting capability, with Python as the named primary. The open-ended 'similar' qualifier has no other named alternatives in the posting.

SIEM and SOAR appear throughout the required qualifications as core platform categories rather than specific named products (e.g., Splunk is only mentioned under preferred certifications). They are captured as required skills reflecting the platform category gate.

Splunk is listed only under preferred certifications, not as a required platform skill.

Cloud platforms (AWS, Azure, GCP) and AI/ML/LLM workflows appear under Preferred qualifications.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): detection engineering.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗