Full Job Description
Senior Security Data Engineer The Senior Security Data Engineer helps build the eyes and ears of EA's security programme. You will lead and evolve the security data pipelines that power detection, investigation, and response across a large, multi-cloud environment.
This is a hands-on security data engineering role with Splunk Enterprise Security at its core, but it isn't simply a Splunk role. You'll work with technologies such as Kafka, APIs, Python, HEC, syslog, cloud platforms, and latest security data services to transform critical security telemetry. You'll also help shape where we go next.
As security data volumes and costs grow, we begin a journey toward federated security analytics, where we do not need to move every piece of data into a traditional SIEM to make it useful. You'll work with our Security Application Architect to explore new architectures, data platforms while influencing EA's longer-term security data strategy. AI is creating an entirely new category of security telemetry.
You'll help determine how we gain visibility into LLM usage, AI APIs, MCP gateways, and enterprise AI services, along with findings from latest security technologies such as Google Model Armor and AIEDR.
Responsibilities
• Own security data onboarding and engineering.
• Evaluate new data sources, determine their security value, and design how they are collected, transformed, filtered available for detections and investigations.
• Build, monitor, and troubleshoot security data flows using technologies such as Kafka, Splunk HEC, syslog, APIs, Python, heavy forwarders, and universal forwarders.
• Lead our Splunk security data environment.
• You will be a technical SME and administrator for Splunk Cloud and Splunk Enterprise Security, with administrative ownership of EA-managed Splunk infrastructure.
• Partner with analysts and detection engineers to ensure telemetry has the quality, context, normalization, and performance needed for detections and investigations. Oversee data reliability.
What We're Looking For
• 5+ years of experience in security engineering, security operations, data engineering, or a related technical discipline.
• Deep hands-on experience with Splunk Cloud/Enterprise and Splunk Enterprise Security.
• Advanced SPL skills and 5+ years of experience with Splunk ingestion, forwarders, data models, CIM, and platform troubleshooting.
• Experience onboarding and transforming data at scale, including parsing, filtering, normalization, enrichment, and optimization. Hands-on experience with technologies such as Kafka, HEC, syslog, REST APIs, Python, and Linux.
Post To
External careers site, Internal careers site
LinkedInID
1449