GovCIO

Cribl Engineer

GovCIO$105K — $145K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience with 8+ years in relevant field
  • 3 years of experience working with the Cribl data engine
  • Strong understanding of data from a security perspective
  • Ability to attain and maintain AOUSC Public Trust clearance
  • Preferred: Cribl Admin Certification
  • Preferred: Experience in a Splunk environment
  • Preferred: Cloud experience

Responsibilities

  • Develop and implement best practices for data ingestion and management
  • Plan and execute Cribl platform upgrades following change control procedures
  • Manage and optimize Cribl's distributed infrastructure for efficiency
  • Continuously monitor and assess Cribl performance metrics
  • Develop and maintain Cribl pipelines for new data sources with filtering and enrichment
  • Migrate data inputs from Splunk forwarder to Cribl for enhanced flexibility
  • Create and uphold standard configurations across environments via Cribl Packs
  • Design workflows to enhance data quality and reduce volume

Benefits

  • Fully remote position within the United States
  • Engagement in high-impact projects within a federal environment
  • Opportunity to work with cutting-edge data management technologies
  • Team collaboration focused on continuous improvement and knowledge sharing
  • Access to professional development and certification opportunities
  • Participation in architecture and design discussions for scalable solutions
Full Job Description
Overview

GovCIO is currently hiring for  Cribl Engineer to support our Administrative Office of the US Courts NLS project. The NLS currently ingest an average of 18-20TB of logging data daily across 60 indexers distributed in 2 data centers. This position is located within the United States and is fully remote.

Responsibilities
  • Develop apply best practices and tools for data ingestion, indexing, and management to optimize data sources and refine data collection processes to capture only pertinent data.
  • Plan and perform Cribl platform upgrades (Leader, Worker, and Edge nodes) following defined change control procedures.
  • Manage and optimize the Cribl distributed infrastructure, ensuring scalability, stability, and efficient data routing.
  • Continuously monitor Cribl performance, including throughput, queue depth, and worker health metrics.
  • Develop and maintain Cribl pipelines for new data sources, implementing filtering, sampling, and enrichment logic.
  • Migrate existing Splunk forwarder-based data inputs to Cribl for improved control and flexibility.
  • Build and maintain Cribl Packs for standardized configurations across multiple environments.
  • Implement data reduction and enhancement workflows to minimize ingestion volume and improve data quality.
  • Maintain and enhance Ansible playbooks for automated deployments, configurations, and upgrades.
  • Integrate GitOps CI/CD pipelines (e.g., GitLab, Jenkins, Terraform) to manage configuration-as-code for both Splunk and Cribl.
  • Develop, test, and review merge requests related to dashboards, alerts, saved searches, and data onboarding pipelines.
  • Perform Splunk core upgrades (indexers, search heads, cluster masters, deployers) ensuring backward compatibility and minimal downtime.
  • Upgrade and validate Splunk Add-ons and Apps, maintaining functionality and CIM compliance.
  • Develop and maintain custom props, transforms, eventtypes, and lookups to normalize data consistently.
  • Ensure CIM compliance for all add-ons and sourcetypes used across the platform.
  • Handle escalations from Operations and perform deep-dive troubleshooting on ingestion, parsing, or performance issues.
  • Perform break/fix analysis on Splunk core services such as KVStore, clustering, deployment server, and scheduler.
  • Conduct performance tuning for search optimization, bucket management, and scheduler balancing across SHC.
  • Design and maintain retention, archival, and index management strategies to align with business and compliance goals.
  • Manage license allocation, volume forecasting, and capacity planning across indexer clusters.
  • Develop and maintain monitoring and alerting integrations for Cribl and Splunk infrastructure health.
  • Collaborate with Operations on incident triage, root cause analysis, and postmortem documentation.
  • Create and maintain runbooks and engineering guides for deployments, upgrades, and troubleshooting.
  • Participate in architecture and design discussions to ensure Splunk and Cribl meet enterprise scaling and reliability needs.
  • Implement security and compliance controls including token rotation, TLS configurations, and secret management via Vault or GCP Secret Manager.
  • Perform disaster recovery testing and validate replication and failover processes across clusters.
  • Collaborate with governance teams to align on data retention, anonymization, and privacy requirements.
  • Support continuous improvement by analyzing ingestion efficiency, performance benchmarks, and automation opportunities.
  • Lead knowledge-sharing sessions and technical handoffs with Operations for newly deployed features or pipelines.
Qualifications

Bachelor's with 8+ years (or commensurate experience)

 

Required Skills and Experience

  • 3 years of experience with Cribl data engine
  • Understanding of Data from a Security Perspective

Clearance Required:  Must be able to attain and maintain AOUSC Public Trust

Preferred Skills and Experience

  • Cribl Admin Cert
  • Experience in a Splunk Environment
  • Cloud Experience
Posted Salary RangeUSD $105,000.00 - USD $145,000.00 /Yr.

About GovCIO

GovCIO is a technology and consulting firm that provides IT solutions to government agencies. The company specializes in cloud computing, cybersecurity, and digital transformation. GovCIO's mission is to help government agencies improve their IT infrastructure and enhance their services to the public. The company was founded in 2015 and is headquartered in Washington, DC.
Learn more about GovCIO
Size
50 employees
Industry
Founded
2015

Similar Jobs

More Jobs at GovCIO

More Information Technology Jobs

Find similar Cribl Engineer jobs: