Senior Cribl Engineer / Security Data Engineer
TSG Risk Management Charlotte, North Carolina, United States · $170K–$220K/yr
Security and Investigations · 11-50 employees
About the role
Develop, maintain, and optimize scalable data processing pipelines using Cribl LogStream and integrate them with security platforms. Collaborate with cross-functional teams to onboard security telemetry and ensure high-quality data solutions for analytics and incident response.
What they look for
Requirements
Requires at least 3 years of experience with Cribl LogStream administration and 2 years of hands-on Snowflake data engineering. Candidates should possess strong scripting skills in Python or JavaScript and familiarity with security data normalization and OCSF standards.
Full description
Senior Cribl Engineer / Security Data Engineer
Location: Charlotte, NC preferred. Candidates in New York City, Los Angeles, Southern California, or other locations may also be considered.
Work Model: Flexible hybrid or remote
Position Overview
Seeking an experienced Senior Cribl Engineer / Security Data Engineer to develop, maintain, and optimize scalable data pipelines utilizing Cribl LogStream. The ideal candidate should have deep knowledge of Cribl architecture, extensive hands-on experience in data engineering, and the ability to improve data ingestion and processing workflows. Familiarity with security operations, SIEM platforms, the Open Cybersecurity Schema Framework (OCSF), security log data, AWS cloud services, and modern data platforms such as Snowflake and Databricks is highly desirable.
Responsibilities
- Develop, implement, and maintain data processing pipelines within Cribl LogStream.
- Configure and optimize data routing, transformation, enrichment, filtering, normalization, and data quality processes.
- Develop and support integrations between Cribl, AWS, SIEM platforms, security analytics tools, and enterprise security lake data platforms.
- Build, troubleshoot, and optimize automated data ingestion and onboarding workflows.
- Onboard and validate security telemetry for SIEM, detection engineering, threat hunting, incident response, and security analytics use cases.
- Collaborate with Security Operations, Detection Engineering, Data Engineering, Infrastructure, and Analytics teams to deliver reliable, scalable, and high-quality data solutions.
- Monitor pipeline performance, resolve issues, and implement continuous improvements.
- Document pipeline configurations, operational procedures, and data flows.
- Develop, create, and maintain Snowflake database objects including databases, schemas, tables, views, streams, tasks, stored procedures, and secure data-sharing configurations.
Qualifications
- 3+ years of experience with Cribl LogStream administration, configuration, and pipeline development.
- 2+ years of hands-on experience with Snowflake administration, architecture, and data engineering in large-scale enterprise environments.
- Experience designing and supporting large-scale security data ingestion, transformation, and processing pipelines utilizing platforms such as Snowflake and Databricks.
- Experience with scripting languages (e.g., Python, JavaScript) for pipeline automation.
- Experience onboarding and managing enterprise security data within SIEM, security data lake, or security analytics environments.
- Familiarity with OCSF, security data normalization, governance, compliance, and other security telemetry best practices.
- Excellent problem-solving skills, ability to debug complex pipeline issues, and strong analytical thinking
- Experience designing, creating, and managing Snowflake databases, schemas, tables, views, streams, tasks, stored procedures, and data pipelines
- Experience with Snowflake Cortex, Snowpark, Python UDFs, stored procedures, and advanced automation frameworks.