Air InfoSec, LLC Logo

Air InfoSec, LLC

Security Data Engineer (Cribl)

Posted 6 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Designs and maintains Cribl data models and security log pipelines, routing and transforming telemetry into enterprise SIEM platforms. Supports SIEM, XDR, vulnerability management, DLP, endpoint security, Linux sensors, system hardening, threat detection, and defensive security architecture. Develops Python and Bash automation, integrations, and security controls while troubleshooting complex data issues. The role is fully remote within the United States, includes occasional South Carolina onsite work, and requires on-call participation.
The summary above was generated by AI

This is a remote position.

The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines.
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
  • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
  • Support SIEM administration, analysis, and reporting.
  • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
  • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
  • Develop security automation and integrations using Python and Bash.
  • Support threat detection, incident-detection activities, and security-control implementation and validation.
  • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
  • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.

Requirements

Minimum Qualifications - Candidates must meet all minimum qualifications

  • Hands-on Cribl data modeling experience.
  • Cribl log-pipeline design and implementation experience.
  • Strong understanding of enterprise security architecture and engineering principles.
  • Experience implementing and supporting enterprise security tools.
  • Exposure to SIEM technologies.
  • Exposure to XDR technologies.
  • Exposure to vulnerability-management technologies.
  • Exposure to Data Loss Prevention (DLP) technologies.
  • Exposure to endpoint-security technologies.
  • Experience developing automation and integrations using Python and/or Bash.
  • Knowledge of cybersecurity best practices.
  • Threat-detection experience.
  • Defensive-security knowledge.
  • Linux operating-system experience.
  • Windows operating-system experience.
  • System-hardening experience.
  • Security-configuration experience.
  • Understanding of networking concepts.
  • Understanding of security protocols.
  • Understanding of secure-system design.
  • 5 years of experience supporting large IT environments and/or enterprise system deployments.
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.

Preferred Qualifications

  • Advanced Cribl Stream experience.
  • SIEM administration experience.
  • SIEM analysis experience.
  • SIEM reporting experience.
  • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
  • Experience building and deploying Linux-based security sensors.
  • Enterprise cybersecurity engineering experience.
  • Security architecture experience.
  • Security automation experience.
  • Security-system integration experience.
  • Knowledge of the NIST Cybersecurity Framework (NIST CSF).
  • Knowledge of CJIS requirements.
  • Knowledge of IRS Publication 1075.
  • Knowledge of CMS MARS-E.
  • CISSP certification.
  • Security+ certification.
  • Location in or near South Carolina with the ability to occasionally report onsite.

Additional Requirements

  • Successful completion of a 7-year standard criminal background check.
  • Successful completion of a full credit-history check.
  • Successful completion of a driving-record (MVR) check.
  • Successful completion of a 10-panel drug screen.
  • E-Verify employment eligibility verification.
  • Successful completion of a SLED check.
  • Ability to obtain and maintain annual CJIS certification.
  • Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate.
  • Participation in an on-call roster.
Work Location and Schedule

Location: Remote within the United States (agency located at 4430 Broad River Road, Columbia, South Carolina 29210).
Schedule: Day schedule, 40 hours per week, with on-call roster participation.
Work Arrangement: 100% remote, with occasional onsite work in South Carolina if requested.


All required experience should be clearly and explicitly documented in the resume.




Similar Jobs

12 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
95K-161K Annually
Entry level
95K-161K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Provides advanced technical support for GitLab deployments serving U.S. government customers in secure, air-gapped, and regulated environments. Investigates Linux, application, infrastructure, and code issues; analyzes logs and performance; develops troubleshooting tools and documentation; partners with Engineering and Product; participates in on-call rotations, customer support, hiring, and process improvement.
Top Skills: Ai/Llm GatewaysBashCi/CdDisa StigGitGitlab DuoKubernetesLinuxOpenshiftRubyRuby On RailsSelinux
12 Minutes Ago
Easy Apply
Remote
United States of America
Easy Apply
165K-175K Annually
Mid level
165K-175K Annually
Mid level
Information Technology • Cybersecurity
Provides technical product expertise and presentations to prospective customers, helping improve their security posture and positioning Huntress solutions. Partners with Sales, Marketing, Support, and Engineering to identify customer needs and product improvements. Reviews security issues with technical teams, supports MSP and VAR customers, and travels approximately 25% to meet customers.
Top Skills: AWSAzureCybersecurity FrameworksElasticGCPMalware AnalysisPsasRmmsSandbox AnalysisSIEMSplunkThreat Intelligence
13 Minutes Ago
Remote or Hybrid
United States
Mid level
Mid level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Leads a Citizen IT team supporting Salesforce and PEGA applications through configuration, administration, troubleshooting, reporting, workflow management, training, and change management. Oversees Salesforce business analysts, partners with development and service leadership, improves data quality and processes, monitors performance, establishes KPIs, manages stakeholders, and drives platform adoption, productivity, and client satisfaction.
Top Skills: Microsoft Power AutomateMicrosoft Power BiPegaPythonSalesforceSalesforce Service Cloud

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account