TSG Risk Management

Senior Cribl Engineer / Security Data Engineer

TSG Risk Management Charlotte, North Carolina, United States · $170K–$220K/yr

Security and Investigations · 11-50 employees

20 h ago
Remote Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Develop, maintain, and optimize scalable data processing pipelines using Cribl LogStream and integrate them with security platforms. Collaborate with cross-functional teams to onboard security telemetry and ensure high-quality data solutions for analytics and incident response.

What they look for

Cribl LogStream Snowflake Data Engineering Security Operations AWS Python JavaScript SIEM OCSF Data Pipelines Detection Engineering Automation Data Normalization Databricks Snowflake Cortex Snowpark

Requirements

Requires at least 3 years of experience with Cribl LogStream administration and 2 years of hands-on Snowflake data engineering. Candidates should possess strong scripting skills in Python or JavaScript and familiarity with security data normalization and OCSF standards.

Full description

Senior Cribl Engineer / Security Data Engineer

Location: Charlotte, NC preferred. Candidates in New York City, Los Angeles, Southern California, or other locations may also be considered.

Work Model: Flexible hybrid or remote

Position Overview

Seeking an experienced Senior Cribl Engineer / Security Data Engineer to develop, maintain, and optimize scalable data pipelines utilizing Cribl LogStream. The ideal candidate should have deep knowledge of Cribl architecture, extensive hands-on experience in data engineering, and the ability to improve data ingestion and processing workflows. Familiarity with security operations, SIEM platforms, the Open Cybersecurity Schema Framework (OCSF), security log data, AWS cloud services, and modern data platforms such as Snowflake and Databricks is highly desirable.

Responsibilities

  • Develop, implement, and maintain data processing pipelines within Cribl LogStream.
  • Configure and optimize data routing, transformation, enrichment, filtering, normalization, and data quality processes.
  • Develop and support integrations between Cribl, AWS, SIEM platforms, security analytics tools, and enterprise security lake data platforms.
  • Build, troubleshoot, and optimize automated data ingestion and onboarding workflows.
  • Onboard and validate security telemetry for SIEM, detection engineering, threat hunting, incident response, and security analytics use cases.
  • Collaborate with Security Operations, Detection Engineering, Data Engineering, Infrastructure, and Analytics teams to deliver reliable, scalable, and high-quality data solutions.
  • Monitor pipeline performance, resolve issues, and implement continuous improvements.
  • Document pipeline configurations, operational procedures, and data flows.
  • Develop, create, and maintain Snowflake database objects including databases, schemas, tables, views, streams, tasks, stored procedures, and secure data-sharing configurations.

Qualifications

  • 3+ years of experience with Cribl LogStream administration, configuration, and pipeline development.
  • 2+ years of hands-on experience with Snowflake administration, architecture, and data engineering in large-scale enterprise environments.
  • Experience designing and supporting large-scale security data ingestion, transformation, and processing pipelines utilizing platforms such as Snowflake and Databricks.
  • Experience with scripting languages (e.g., Python, JavaScript) for pipeline automation.
  • Experience onboarding and managing enterprise security data within SIEM, security data lake, or security analytics environments.
  • Familiarity with OCSF, security data normalization, governance, compliance, and other security telemetry best practices.
  • Excellent problem-solving skills, ability to debug complex pipeline issues, and strong analytical thinking
  • Experience designing, creating, and managing Snowflake databases, schemas, tables, views, streams, tasks, stored procedures, and data pipelines
  • Experience with Snowflake Cortex, Snowpark, Python UDFs, stored procedures, and advanced automation frameworks.