Security Data Engineer (Cribl)

Posted Yesterday
Hiring Remotely in USA
Remote
Senior level
Information Technology • Security • Consulting • Cybersecurity
The Role
Designs and maintains Cribl data models and security log pipelines, routing and transforming telemetry into enterprise SIEM platforms. Supports SIEM, XDR, vulnerability management, DLP, endpoint security, Linux sensors, system hardening, threat detection, and defensive security architecture. Develops Python and Bash automation, integrations, and security controls while troubleshooting complex data issues. The role is fully remote within the United States, includes occasional South Carolina onsite work, and requires on-call participation.
Summary Generated by Built In

This is a remote position.

The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines.
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
  • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
  • Support SIEM administration, analysis, and reporting.
  • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
  • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
  • Develop security automation and integrations using Python and Bash.
  • Support threat detection, incident-detection activities, and security-control implementation and validation.
  • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
  • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.

Requirements

Minimum Qualifications - Candidates must meet all minimum qualifications

  • Hands-on Cribl data modeling experience.
  • Cribl log-pipeline design and implementation experience.
  • Strong understanding of enterprise security architecture and engineering principles.
  • Experience implementing and supporting enterprise security tools.
  • Exposure to SIEM technologies.
  • Exposure to XDR technologies.
  • Exposure to vulnerability-management technologies.
  • Exposure to Data Loss Prevention (DLP) technologies.
  • Exposure to endpoint-security technologies.
  • Experience developing automation and integrations using Python and/or Bash.
  • Knowledge of cybersecurity best practices.
  • Threat-detection experience.
  • Defensive-security knowledge.
  • Linux operating-system experience.
  • Windows operating-system experience.
  • System-hardening experience.
  • Security-configuration experience.
  • Understanding of networking concepts.
  • Understanding of security protocols.
  • Understanding of secure-system design.
  • 5 years of experience supporting large IT environments and/or enterprise system deployments.
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.

Preferred Qualifications

  • Advanced Cribl Stream experience.
  • SIEM administration experience.
  • SIEM analysis experience.
  • SIEM reporting experience.
  • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
  • Experience building and deploying Linux-based security sensors.
  • Enterprise cybersecurity engineering experience.
  • Security architecture experience.
  • Security automation experience.
  • Security-system integration experience.
  • Knowledge of the NIST Cybersecurity Framework (NIST CSF).
  • Knowledge of CJIS requirements.
  • Knowledge of IRS Publication 1075.
  • Knowledge of CMS MARS-E.
  • CISSP certification.
  • Security+ certification.
  • Location in or near South Carolina with the ability to occasionally report onsite.

Additional Requirements

  • Successful completion of a 7-year standard criminal background check.
  • Successful completion of a full credit-history check.
  • Successful completion of a driving-record (MVR) check.
  • Successful completion of a 10-panel drug screen.
  • E-Verify employment eligibility verification.
  • Successful completion of a SLED check.
  • Ability to obtain and maintain annual CJIS certification.
  • Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate.
  • Participation in an on-call roster.
Work Location and Schedule

Location: Remote within the United States (agency located at 4430 Broad River Road, Columbia, South Carolina 29210).
Schedule: Day schedule, 40 hours per week, with on-call roster participation.
Work Arrangement: 100% remote, with occasional onsite work in South Carolina if requested.


All required experience should be clearly and explicitly documented in the resume.




Skills Required

  • Hands-on Cribl data modeling experience
  • Cribl log-pipeline design and implementation experience
  • Strong understanding of enterprise security architecture and engineering principles
  • Experience implementing and supporting enterprise security tools
  • Exposure to SIEM technologies
  • Exposure to XDR technologies
  • Exposure to vulnerability-management technologies
  • Exposure to Data Loss Prevention technologies
  • Exposure to endpoint-security technologies
  • Experience developing automation and integrations using Python and/or Bash
  • Knowledge of cybersecurity best practices
  • Threat-detection experience
  • Defensive-security knowledge
  • Linux operating-system experience
  • Windows operating-system experience
  • System-hardening experience
  • Security-configuration experience
  • Understanding of networking concepts
  • Understanding of security protocols
  • Understanding of secure-system design
  • 5 years of experience supporting large IT environments and/or enterprise system deployments
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience
  • Advanced Cribl Stream experience
  • SIEM administration, analysis, and reporting experience
  • Experience with Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch
  • Experience building and deploying Linux-based security sensors
  • Enterprise cybersecurity engineering experience
  • Security architecture experience
  • Security automation experience
  • Security-system integration experience
  • Knowledge of the NIST Cybersecurity Framework
  • Knowledge of CJIS requirements
  • Knowledge of IRS Publication 1075
  • Knowledge of CMS MARS-E
  • CISSP certification
  • Security+ certification
  • Location in or near South Carolina with ability to occasionally report onsite
  • Successful completion of a 7-year criminal background check
  • Successful completion of a full credit-history check
  • Successful completion of a driving-record check
  • Successful completion of a 10-panel drug screen
  • E-Verify employment eligibility verification
  • Successful completion of an SLED check
  • Ability to obtain and maintain annual CJIS certification
  • Availability for occasional onsite needs in South Carolina
  • Participation in an on-call roster
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company

What We Do

Air InfoSec is a veteran-owned and led cybersecurity consulting and staffing firm based in Austin, Texas, focused on enhancing government security through expert staff placement.

Similar Jobs

Toast Logo Toast

Principal Product Manager

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
US
5000 Employees
190K-304K Annually
In-Office or Remote
Boise, ID, USA
10000 Employees
35K-55K Annually
In-Office or Remote
Salt Lake City, UT, USA
10000 Employees
35K-55K Annually
In-Office or Remote
Phoenix, AZ, USA
10000 Employees
35K-55K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account