Lead SIEM Analyst (CrowdStrike , Cribl)

Sorry, this job was removed at 10:10 p.m. (CST) on Tuesday, Jan 20, 2026
Be an Early Applicant
3 Locations
In-Office
eCommerce • Logistics
The Role

Scope :

This role will focus on building, operating, and continuously improving SIEM capabilities that enable proactive threat detection, efficient investigations, and scalable security monitoring across a global, cloud-first enterprise.

What You’ll do:

  • Design, implement, and operate SIEM capabilities using CrowdStrike NGSIEM
  • Lead onboarding of new log sources, including development of custom parsers, field normalization, and data validation
  • Build, tune, and maintain detection rules, correlation logic, and alerting aligned with real-world threats and MITRE ATT&CK
  • Create and maintain dashboards and visualizations to support SOC operations, leadership reporting, and compliance requirements
  • Use CrowdStrike Query Language (CQL) for advanced investigations, threat hunting, and data analysis
  • Design and manage log ingestion pipelines using Cribl, including routing, enrichment, filtering, and transformation
  • Develop and maintain automation and API-based integrations to streamline data onboarding, detection deployment, and operational workflows
  • Partner with SOC analysts, cloud teams, and platform owners to ensure high-quality, security-relevant telemetry
  • Act as a technical escalation point for SIEM-related investigations and incident response
  • Continuously improve detection fidelity, data quality, and SIEM performance
  • Support audit and compliance initiatives (e.g., PCI-DSS, ISO 27001, SOC 2) through monitoring, reporting, and evidence generation
  • Document SIEM architecture, data flows, detection logic, and operational runbooks
  • Security Tech Stack / Tools
  • SIEM & Detection
  • CrowdStrike NGSIEM (primary)
  • Splunk (acceptable alternative where NGSIEM experience is not available)
  • Detection engineering, correlation rules, dashboards, and alerting
  • Log & Data Engineering
  • Cribl (pipelines, routing, enrichment, filtering)
  • Custom parser development and log normalization
  • Automation & Integration
  • Python, PowerShell
  • REST APIs, Webhooks
  • Automation for SIEM operations and integrations
  • Any SOAR Tool Experience

What We’re Looking For

  • 5 - 8 years of hands-on experience in SIEM engineering, detection engineering, or security monitoring
  • Strong hands-on experience with CrowdStrike NGSIEM is required
    • Candidates without NGSIEM experience must demonstrate deep, hands-on SIEM engineering experience using Splunk in enterprise environments
  • Proven experience developing custom parsers and onboarding diverse log sources
  • Hands-on experience with CrowdStrike Query Language (CQL) or equivalent SIEM query languages
  • Strong experience building detection rules, dashboards, and alerting for SOC operations
  • Hands-on experience with Cribl for log routing, enrichment, and pipeline optimization
  • Experience with automation and API-based integrations
  • Solid understanding of security telemetry, log formats, and large-scale log ingestion architectures
  • Ability to work effectively in a global, fast-paced environment

Preferred Skills / Nice to Have

  • CrowdStrike Certified Security Engineer (CCSE) – strong plus
  • Experience supporting SOC or MSSP environments
  • Familiarity with compliance-driven monitoring (PCI-DSS, ISO 27001, SOC 2)
  • Experience leading SIEM modernization or large-scale onboarding initiatives
  • Strong communication skills and ability to collaborate across engineering and security teams

Our Values

If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success – and the success of our customers. Does your heart beat like ours? Find out here: Core Values

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Similar Jobs

MassMutual India Logo MassMutual India

IT Asset Management

Big Data • Fintech • Information Technology • Insurance • Financial Services
In-Office
Hyderabad, Telangana, IND
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Tufin Logo Tufin

Technical Account Manager

Security • Cybersecurity
Remote or Hybrid
India
500 Employees

Nasuni Logo Nasuni

Principal Software Engineer

Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Easy Apply
Hybrid
Hyderabad, Telangana, IND
550 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Scottsdale, AZ
5,001 Employees
Year Founded: 1985

What We Do

Blue Yonder is the world leader in digital supply chain and omni-channel commerce fulfillment. Our intelligent, end-to-end platform enables retailers, manufacturers and logistics providers to seamlessly predict, pivot and fulfill customer demand. With Blue Yonder, you can make more automated, profitable business decisions that deliver greater growth and re-imagined customer experiences. Blue Yonder - Fulfill your Potential

Blue Yonder’s tagline “Fulfill Your Potential” reflects the company’s mission to empower every organization and person on the planet to fulfill their potential. Each day, our global teams of associates and business partners work together to accelerate global economic growth, increase sustainability and prosperity with a Sonoran Spirit.

Similar Companies Hiring

ClickMint Thumbnail
Marketing Tech • Generative AI • eCommerce • AdTech
Malibu, CA
9 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account