Cribl Data Engineer, Cybersecurity and SIEMLocation:Charlotte, NC preferred. Candidates in New York City, Los Angeles, Southern California, or other locations may also be considered.
Work Model:Flexible hybrid or remote
Position OverviewWe are seeking an experienced Cribl Data Engineer to support the design, development, and optimization of cybersecurity data pipelines across SIEM and data lake environments.
The ideal candidate will bring hands-on Cribl engineering experience combined with a strong understanding of cybersecurity data. This individual will help manage the flow of security data from source systems through Cribl and into data lakes and SIEM platforms. Experience with Databricks, Snowflake, connector development, and other data ingestion technologies is highly valued.
This is a hands-on engineering role within a small, growing team. The successful candidate must be able to work independently, take an idea and run with it, solve open-ended technical problems, and clearly communicate their decisions and recommendations to technical teams and leadership.
Key Responsibilities- Design, build, maintain, and optimize cybersecurity data pipelines using Cribl.
- Manage security data flows from source systems through Cribl into data lakes and SIEM platforms.
- Develop and maintain connectors and integrations for security data ingestion.
- Configure data routing, parsing, filtering, enrichment, and transformation.
- Support SIEM architecture, engineering, and ongoing platform operations.
- Integrate security data with platforms such as Databricks and Snowflake.
- Troubleshoot complex data ingestion, integration, performance, and pipeline issues.
- Develop scripts and automation to support data processing and pipeline management.
- Ensure the accuracy, security, integrity, and availability of cybersecurity data.
- Partner with cybersecurity, engineering, and data teams to understand requirements and recommend appropriate solutions.
- Evaluate multiple technical approaches and independently determine the best way to solve a problem.
- Clearly explain technical decisions, designs, and troubleshooting findings during team meetings and leadership discussions.
- Create and maintain technical documentation for data pipelines, integrations, and platform configurations.
- Share knowledge and help establish scalable engineering practices within the team.
Required Qualifications- Approximately 4 to 5 years of relevant data engineering, security engineering, or SIEM engineering experience.
- Hands-on experience implementing, configuring, or supporting Cribl in a production environment.
- Strong understanding of cybersecurity data and common security data sources.
- Experience building and maintaining data pipelines for SIEM or security analytics environments.
- Strong knowledge of data routing, parsing, filtering, enrichment, and transformation.
- Experience ingesting data into data lakes or other large-scale data platforms.
- Experience developing connectors, integrations, or APIs between source systems and downstream platforms.
- Proficiency with Python, Bash, or a similar scripting language.
- Experience with cloud platforms such as AWS, Azure, or Google Cloud.
- Understanding of networking, security operations, and security engineering best practices.
- Strong troubleshooting and analytical skills.
- Ability to work independently without needing step-by-step direction.
- Strong written and verbal communication skills.
- Ability to participate confidently in meetings and explain technical work to both technical and nontechnical stakeholders.
Preferred Qualifications- Experience with Databricks and/or Snowflake.
- Experience with SIEM platforms and SIEM architecture.
- Experience with Cribl Stream, Cribl Edge, or other Cribl products.
- Familiarity with OCSF or other cybersecurity data schemas.
- Understanding of frameworks and data models such as NIST, MITRE ATT&CK, or the CIM Object Model.
- Experience working with endpoint, cloud, application, infrastructure, or network security data.
- Knowledge of Windows, macOS, Linux, and Unix operating systems.
- Relevant Cribl, cloud, security, or data engineering certifications.
- Experience supporting security operations or SOAR environments.