Role description
Job Role: Security Tools Engineer with Cequence API Security , AWS, Splunk
Location: Remote
Primary Focus
Deployment and integration of Cequence API Security Wiz Federal Splunk and Cribl.
AWS GovCloud federal government telecom or highly regulated cloud environments.
Handson deployment platform engineering integration automation and operational handover.
We are seeking a handson Security Tools Engineer responsible for deploying configuring integrating and operationalizing enterprise security platforms across cloud and regulated environments.
The role will focus on implementing Cequence API Security Wiz Federal Splunk and Cribl to enable API threat protection cloud security posture management centralized logging telemetry optimization security analytics and SOCready monitoring capabilities.
The engineer will work closely with cloud security operations network application and DevSecOps teams to ensure the deployed platforms are secure scalable compliant and ready for transition into steadystate operations.
Key Responsibilities
Cequence API Security Deployment.
Deploy and configure Cequence API Security across applicable cloud application and API environments.
Integrate Cequence with API gateways load balancers application endpoints and relevant traffic sources.
Configure API discovery inventory behavior analytics risk scoring and attack detection policies.
Enable runtime API protection bot mitigation abuse detection and OWASP API Security monitoring use cases.
Integrate Cequence s and findings with SplunkSOC workflows for investigation and response.
Develop deployment documentation integration guides runbooks and handover material for operations teams.
Wiz Federal Deployment CNAPP Engineering.
Deploy and configure Wiz Federal in AWS GovCloud or regulated cloud environments.
Onboard AWS accounts and workloads into Wiz Federal using approved connector and access models.
Configure CSPM CWPP vulnerability exposure management compliance policies and cloud risk dashboards
Support attack path analysis cloud entitlement visibility prioritization of toxic combinations and workload risk reporting.
Integrate Wiz Federal findings with Splunk Cribl ticketing and operational workflows where required.
Support FedRAMP NIST 80053 FIPS CMMC and Zero Trustaligned cloud security controls.
Splunk Deployment SIEM Engineering.
Deploy and configure Splunk components including Indexers Search Heads Heavy Forwarders and Universal Forwarders.
Design and implement log ingestion parsing normalization field extraction indexing and retention strategies.
Onboard security telemetry from cloud network endpoint application API security and CNAPP platforms.
Develop dashboards s correlation searches reports and operational views for SOC and security engineering teams.
Troubleshoot ingestion issues parsing failures data gaps performance bottlenecks and platform health concerns.
Support Splunk integration with Cribl for routing filtering enrichment and ingestion optimization.
Cribl Deployment Telemetry Pipeline Engineering.
Deploy and configure Cribl Stream infrastructure to support secure and scalable telemetry routing.
Build pipelines for filtering enrichment transformation redaction sampling and destinationbased routing.
Integrate Cribl with Splunk cloudnative logging services security platforms and observability destinations.
Optimize data ingestion volumes improve log quality and reduce unnecessary SIEM storage and processing costs.
Configure secure source and destination connectivity certificates access controls and pipeline monitoring.
Create reusable data onboarding patterns and documentation for future tool and log source integrations.
Platform Integration Automation Handover.
Integrate Cequence Wiz Federal Splunk and Cribl into a unified security monitoring and response ecosystem.
Use APIs scripts and InfrastructureasCode practices to standardize repeatable deployments where applicable.
Collaborate with SOC teams to align s dashboards data models and investigation workflows.
Prepare deployment plans configuration workbooks architecture diagrams operational runbooks and knowledge transfer material.
Support testing validation troubleshooting golive readiness and transition to steadystate support teams.
Required Skills
Security Platforms
Cequence API Security
Wiz Federal Wiz CNAPP
Splunk Enterprise Splunk Cloud
Cribl Stream
Cloud Security
AWS GovCloud
AWS CloudTrail Security Hub GuardDuty Security Lake
IAM federation access governance
Zero Trust and cloud security architecture
Engineering Automation
Terraform or CloudFormation
Python PowerShell Bash
REST APIs and platform integrations
CICD and deployment automation
Log parsing normalization route