Security Observability Engineer
Core
Lead the migration, optimization, and secure operation of log ingestion and observability pipelines for security and IT logs.
Role type
Senior Security Observability Engineer
Builds
Secure, scalable log ingestion pipelines and SIEM infrastructure
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Splunk SIEM engineering, Cribl Stream/Edge, machine data transport protocols, log parsing and tuning, Python scripting, operational dashboarding
Preferred skills
Clustered/HA Cribl and Splunk deployments, Splunk ES or Cribl certifications
Technologies
Splunk, Cribl Stream, Cribl Edge, syslog, HEC, TCP, UDP
Responsibilities
Migrate log sources from Splunk ingestion to Cribl Stream/Edge pipelines; Architect and manage scalable, resilient pipelines with load balancing solutions; Analyze, tune, and securely onboard log sources (firewalls, EDR, cloud, authentication); Develop and maintain Cribl and Splunk configurations for security analytics; Ensure optimal distribution of logging workload to prevent bottlenecks; Collaborate with SOC and IR teams to ensure efficient log delivery for detection; Apply and document security policies for log routing and retention; Track and report ingest reduction and pipeline health metrics.
Seniority
Senior, hands-on IC