Cybersecurity Engineer I
Core
Maintain and enhance enterprise log management infrastructure to ensure reliable, secure, and scalable ingestion of security-relevant data.
Role type
Cybersecurity Engineer I (Log Management & SIEM)
Builds
High-availability log server clusters, ingestion pipelines, and security dashboards for the enterprise.
Domain
Cybersecurity / Log Management / SIEM Engineering
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Syslog technologies (NXLOG, syslog-ng, Snare, rsyslog), Linux administration, Python/Shell scripting, Cloud log ingestion (AWS, Azure, GCP), API integration, Log parsing and normalization, SIEM administration, Backup and retention strategies.
Preferred skills
SOAR platforms and playbook development, Containerized environments logging (Docker, Kubernetes), Splunk Certified Architect, Elastic Certified Engineer, CISSP, GIAC.
Technologies
NXLOG, syslog-ng, Snare, rsyslog, Python, Shell, AWS, Azure, GCP, Docker, Kubernetes, Splunk, Elastic.
Responsibilities
Administer and maintain log servers including upgrades, patching, and migrations; Manage log archiving, retention policies, and backup strategies; Perform log parsing, normalization, and selective event ingestion; Develop scripts for log processing and automation; Create dashboards, reports, and configure alerts for log ingestion health; Work closely with SOC, IR, and infrastructure teams; Document log source configurations and architectural decisions.
Seniority
Individual Contributor (IC), Entry to Mid-level