Cribl Security Engineer
Role details
Job location
Tech stack
Job description
Overview / Summary This position serves as a Data Modeling Security Engineer focused on Cribl ingestion and log pipeline design within an enterprise security environment. The role supports security architects and engineering staff in designing, implementing, and maintaining Cribl-based data modeling solutions in a large-scale security organization. The contractor will also provide hands-on technical support across multiple security disciplines and contribute to improving enterprise security architecture and operations., + Assist in planning, design, deployment, and operational support of enterprise security platforms, with primary focus on Cribl data modeling and log pipeline ingestion
-
Support Security Information and Event Management (SIEM) design, configuration, and operations
-
Assist with design and configuration of Linux-based security sensors and endpoint monitoring tools
-
Support additional enterprise security platforms including XDR, vulnerability management, DLP, and security awareness tools
-
Collaborate with security architects to design and implement enterprise security solutions aligned with business goals, regulatory requirements, and risk tolerance
-
Design and implement countermeasures for known threats and support mitigation strategies for emerging threats
-
Ensure consistent application of security controls across enterprise systems and validate control effectiveness
-
Support incident detection and response through log monitoring, analysis, and reporting
-
Develop technical documentation, implementation guides, and standard operating procedures
-
Participate in on-call rotation
-
Perform other duties as assigned
Requirements
-
Strong experience with Cribl data modeling and log pipeline design/implementation
-
Strong understanding of enterprise security architecture and engineering principles
-
Experience supporting enterprise security tools such as SIEM, XDR, vulnerability management, DLP, and endpoint security solutions
-
Experience with scripting languages such as Python and Bash for automation and integration
-
Knowledge of cybersecurity best practices, threat detection, and defensive security strategies
-
Experience with Linux and Windows systems, including system hardening and security configuration
-
Understanding of networking concepts, security protocols, and secure system design
-
Bachelor's degree in IT or Information Security OR 8 years of relevant experience in lieu of degree
-
Minimum 5 years supporting large IT environments and/or system deployments
-
Must pass full credit check and criminal background check
-
Must complete and maintain annual CJIS certification
-
Subject to additional screening including 7-year background check, credit history check, MVR, 10-panel drug screen, E-Verify, and SLED check
-
Ability to participate in on-call rotation