Denver, CO

Salary
—
Posted
Aug 1, 2026
Location
Denver, CO
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This is a client-facing security operations engineering role at Deloitte, focused on designing, deploying, and optimizing Google SecOps (Chronicle SIEM and SOAR) environments for enterprise clients. Day-to-day work involves building log ingestion pipelines, developing threat detection rules, automating SOC workflows via SOAR playbooks, and integrating third-party security tools. The role also carries a mentoring and team-lead responsibility over junior practitioners.

Senior level · 9+ years · Full-time

Must have (10)
Google Chronicle SIEMGoogle SecOps SOAR or Google SiemplifyPythonGoStash or LogstashBindplaneCriblNXLogKafkaSIEMSOAR

“or” means any one of them counts — you don't need all of them.

Posted 12 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Kafka12%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
SIEM55%Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 2, 2026. It is a model, not a headcount.

Why we read it this way (7)

No work location is specified in the posting; the CBSA and state fields are left blank. The role may be remote or travel-based given the consulting context, but the posting does not explicitly state remote eligibility.

The title 'Manager' at Deloitte is a mid-career consulting grade, not a people-management title in the traditional sense — the JD describes hands-on IC engineering work with mentoring responsibilities rather than direct-report management, so 15-1212 (Information Security Analysts) is preferred over 11-3021. However, the heavy automation and integration development work (Python scripting, ETL pipelines, SOAR playbook development) creates genuine ambiguity with 15-1252 (Software Developers).

The degree requirement states 'Bachelor's degree … or equivalent work experience,' so no formal degree is hard-gated.

GoStash and Logstash are listed as a paired alternative in the posting ('Python scripting and GoStash or Logstash'); they are captured as a single skill with Logstash as the alternative.

Google Siemplify is listed alongside Google SecOps SOAR as part of the same tool family; captured as an alternative to Google SecOps SOAR.

'Threat detection engineering' is retained as a skill here because the posting explicitly names it as a required area of experience with concrete associated work (writing and tuning detection rules), making it a meaningful technical gate rather than a generic concept.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Threat detection engineering.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗