Security Data Engineering & ETL (Cribl)

Merck & Company
San Francisco, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 184K

Job location

San Francisco, United States of America

Tech stack

Data analysis
Azure
Cloud Computing
Cloud Computing Security
Cloud Engineering
Configuration Management
Computer Security
Information Engineering
Data Governance
ETL
Data Retention
Identity and Access Management
Information Lifecycle Management
Network Segmentation
Security Information and Event Management
Data Streaming
Data Logging
Google Cloud Platform
System Availability
Technical Debt
Infrastructure as Code (IaC)
Data Lake
Bicep
Operational Systems
Data Management
Terraform
Cyber Warfare
Data Pipelines

Job description

We are seeking a CD&A Engineer - Specialist to design, engineer, and operate security data pipelines and cloud infrastructure supporting enterprise-scale analytics and detection platforms. This role focuses on ETL engineering using Cribl and infrastructure-as-code (IaC) across Google Cloud and Azure, enabling reliable, scalable, and cost-effective ingestion and processing of security telemetry., Security Data Engineering & ETL (Cribl)

  • Engineer and operate Cribl pipelines to ingest, parse, enrich, route, and transform high-volume security telemetry.
  • Optimize data flows for performance, reliability, and cost efficiency across security analytics platforms, including SIEM, XDR, and data lakes.
  • Implement and enforce data standards for normalization, metadata enrichment, and data quality validation.
  • Support onboarding of new security data sources and continuous improvement of existing pipelines., * Design, deploy, and maintain cloud infrastructure using Infrastructure as Code (IaC) across Azure and Google Cloud.
  • Manage infrastructure for security data platforms, ingestion services, and supporting components using Terraform, ARM/Bicep, or equivalent tooling.
  • Ensure infrastructure deployments are consistent, repeatable, and auditable across environments (development, test, production).
  • Partner with cloud and platform teams to align infrastructure with enterprise security, networking, and governance standards.

Platform Reliability, Observability & Operations

  • Ensure availability, scalability, and resilience of security data pipelines and supporting infrastructure.
  • Implement monitoring, alerting, and operational metrics for ETL and ingestion services.
  • Participate in incident response and root cause analysis related to data pipeline or infrastructure issues.
  • Proactively identify and remediate performance bottlenecks and operational risks.

Automation & Continuous Improvement

  • Drive automation for infrastructure provisioning, pipeline deployment, and configuration management.
  • Contribute to roadmap planning, technical debt reduction, and operational maturity initiatives.
  • Develop and maintain documentation, standards, and runbooks for data pipelines and infrastructure.
  • Promote reuse and standard patterns across CD&A engineering.

Collaboration & Governance

  • Work closely with Cyber Defense (CFC/SOC), XDR/SIEM engineers, Cloud Security, Platform Engineering, and Compliance teams.
  • Support audit, compliance, and data retention requirements impacting security telemetry.
  • Provide technical input into architecture decisions, onboarding reviews, and platform changes.

Requirements

  • Bachelor's degree
  • Minimum 4 years of experience in security data engineering, cloud engineering, or platform engineering roles.
  • Hands-on experience with Cribl or equivalent security data pipeline / ETL tooling.
  • Strong experience building and managing infrastructure using IaC (Terraform, ARM/Bicep, or similar).
  • Practical experience with Google Cloud and/or Azure.
  • Solid understanding of security telemetry, logging, and data lifecycle concepts.
  • Experience operating platforms in large, enterprise-scale environments.

Required Skills: Certificate Services, Cloud Security, Cybersecurity Analytics, Cybersecurity Operations, Delivery of Security Applications, Design Applications, Identity Access Management (IAM), Incident Response, Information Security, Network Segmentation, Operational Technology (OT) Security, Security Analytics, SLA Management, System Designs, Team Leadership, Technical Advice

Benefits & conditions

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another's thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

The salary range for this role is $117,000.00 - $184,200.00

About the company

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Apply for this position