Cribl Engineer

GuidePoint Security

$120K — $150K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • TS/SCI w/Poly (CI or FS) security clearance required.
  • Over 10 years of experience in logging, observability, or SIEM engineering.
  • 5+ years of experience architecting enterprise scale log/telemetry pipelines.
  • 3+ years of hands-on experience with Cribl Stream and Cribl Edge in production environments.
  • Demonstrated success in operating and scaling pipelines at 5-10+ TB/day.

Responsibilities

  • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains.
  • Build high throughput pipelines with advanced routing, filtering, and enrichment workflows.
  • Optimize system performance across CPU/memory distribution and software transport mechanisms.
  • Engineer secure data flows incorporating governance controls like RBAC and tokenization.
  • Integrate pipelines with various SIEM and analytics ecosystems.
  • Develop reliability frameworks and maintain fleet health metrics.
  • Mentor senior engineers and conduct design reviews for engineering excellence.

Benefits

  • Remote workforce opportunities (U.S. based only with some travel requirements).
  • Zero Deductible PPO plan with significant employer premium contributions or High Deductible Health Plan with HSA contributions.
  • 100% employer-paid group dental insurance for employees.
  • 12 corporate holidays paired with a Flexible Time Off (FTO) program.
  • Healthy allowances for mobile phone and home internet costs.
Full Job Description
We are seeking a highly experienced Cribl Engineer to serve as the principal technical authority for observability pipelines built on Cribl Stream and Cribl Edge. This role is designed for a senior technologist with deep expertise in log/telemetry routing, large scale data engineering, and enterprise-grade observability architectures. You will shape pipeline strategy, design complex routing and transformation logic, drive platform reliability, mentor senior engineers, and serve as the top technical escalation point for Cribl related challenges. Key Responsibilities • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains. • Build high throughput pipelines (multiTB/day) with advanced routing, filtering, enrichment, and replay workflows. • Optimize system performance, worker topology, CPU/memory distribution, queues, and transport mechanisms. • Engineer secure data flows with masking, tokenization, RBAC, PKI/TLS, and other governance controls. • Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms, cloud services). • Develop HA/DR patterns, reliability frameworks, fleet health metrics, and failure mode response processes. • Maintain reusable Cribl packs, shared patterns, runbooks, and operational standards. • Serve as the senior escalation point for Cribl issues; interface with vendor engineering as required. • Mentor engineers, conduct design reviews, drive engineering excellence, and enforce architectural standards. • Support cross functional teams (security, cloud, analytics, infrastructure) on logging and telemetry strategy. Requirements • Must possess a TS/SCI w/Poly (CI or FS) • 10+ years of experience in logging, observability, or SIEM engineering. • 5+ years architecting enterprise scale log/telemetry pipelines. • 3+ years hands-on with Cribl Stream and Cribl Edge in production environments. • Demonstrated success operating and scaling pipelines at 5-10+ TB/day. • Expert-level experience with Splunk forwarding/ingestion, source type management, and indexing practices. • Strong Linux fundamentals; scripting expertise (Python/Bash); Git; automation (Ansible/Terraform). • Strong understanding of transport protocols (HTTP, TCP, TLS/MTLS), Kafka, S3/object storage. • Experience designing secure data flows, including encryption, RBAC, secrets management, and compliance controls. • Demonstrated ability to mentor senior engineers and lead technical decision making. • Certified Cribl Certified Engineer (CCOE) or equivalent Cribl product expertise. • Must possess the following DoD 8570.01-M certifications or be willing to obtain within 30 days of hire: • Information Assurance Technician (IAT) Level II certification (currently Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND). • IAT Level III certification requirements (currently CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH). • Cyber Security Service Provider (CSSP) - Infrastructure Support (IS) certification requirements (currently CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND). Preferred Qualifications • Expertise creating and maintaining Cribl Packs and reusable pipelines. • Experience with cloud telemetry (AWS, Azure, hybrid) and cross domain data movement patterns. • Familiarity with NIST / CIS control frameworks and secure engineering practices. • Experience building observability frameworks for large distributed systems. • Vendor engagement experience (Cribl PS, product teams, troubleshooting escalations). Some added perks.... • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans • 12 corporate holidays and a Flexible Time Off (FTO) program • Healthy mobile phone and home internet allowance • Eligibility for retirement plan after 2 months at open enrollment • Pet Benefit Option

Similar Jobs

More Jobs at GuidePoint Security

  • Cribl Engineer
    $120K — $150K *
    Southern Md Facility, MD 20697 (Prince Georges County)
    Aerospace & Defense
    In-Person
  • Cribl Engineer
    $120K — $150K *
    Washington, DC 20011 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • Senior Network Security Engineer
    $100K — $130K *
    Chantilly, VA 20152 (Loudoun County)
    Aerospace & Defense
    In-Person
  • Account Executive (Memphis)
    $80K — $120K *
    Memphis, TN 38109 (Shelby County)
    Information Technology
    In-Person
  • Senior Cloud Engineer
    $120K — $150K *
    Chantilly, VA 20152 (Loudoun County)
    Information Technology
    In-Person

More Aerospace & Defense Jobs

Find similar Cribl Engineer jobs: