Cribl Data Engineer, Cybersecurity and SIEM

The Sugrue Group Limited Liability Company
Charlotte, NC, United States
4 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Apple Mac Systems Microsoft Azure Bash Shell Big Data Unix Cloud Computing Cyber Security System Configuration Information Engineering Linux
+16 more
Python (Programming Language) Network Security Object-Oriented Software Development Parsing Security Information and Event Management Data Streaming Systems Integration Data Processing Scripting Google Cloud Data Ingestion Snowflake Mitre Att&ck Data Lakes Data Pipelines Databricks

Job description

We are seeking an experienced Cribl Data Engineer to support the design, development, and optimization of cybersecurity data pipelines across SIEM and data lake environments., + Design, build, maintain, and optimize cybersecurity data pipelines using Cribl.

  • Manage security data flows from source systems through Cribl into data lakes and SIEM platforms.
  • Develop and maintain connectors and integrations for security data ingestion.
  • Configure data routing, parsing, filtering, enrichment, and transformation.
  • Support SIEM architecture, engineering, and ongoing platform operations.
  • Integrate security data with platforms such as Databricks and Snowflake.
  • Troubleshoot complex data ingestion, integration, performance, and pipeline issues.
  • Develop scripts and automation to support data processing and pipeline management.
  • Ensure the accuracy, security, integrity, and availability of cybersecurity data.
  • Partner with cybersecurity, engineering, and data teams to understand requirements and recommend appropriate solutions.
  • Evaluate multiple technical approaches and independently determine the best way to solve a problem.
  • Clearly explain technical decisions, designs, and troubleshooting findings during team meetings and leadership discussions.
  • Create and maintain technical documentation for data pipelines, integrations, and platform configurations.
  • Share knowledge and help establish scalable engineering practices within the team.

Requirements

The ideal candidate will bring hands-on Cribl engineering experience combined with a strong understanding of cybersecurity data. This individual will help manage the flow of security data from source systems through Cribl and into data lakes and SIEM platforms. Experience with Databricks, Snowflake, connector development, and other data ingestion technologies is highly valued. This is a hands-on engineering role within a small, growing team. The successful candidate must be able to work independently, take an idea and run with it, solve open-ended technical problems, and clearly communicate their decisions and recommendations to technical teams and leadership., + Approximately 4 to 5 years of relevant data engineering, security engineering, or SIEM engineering experience.

  • Hands-on experience implementing, configuring, or supporting Cribl in a production environment.
  • Strong understanding of cybersecurity data and common security data sources.
  • Experience building and maintaining data pipelines for SIEM or security analytics environments.
  • Strong knowledge of data routing, parsing, filtering, enrichment, and transformation.
  • Experience ingesting data into data lakes or other large-scale data platforms.
  • Experience developing connectors, integrations, or APIs between source systems and downstream platforms.
  • Proficiency with Python, Bash, or a similar scripting language.
  • Experience with cloud platforms such as AWS, Azure, or Google Cloud.
  • Understanding of networking, security operations, and security engineering best practices.
  • Strong troubleshooting and analytical skills.
  • Ability to work independently without needing step-by-step direction.
  • Strong written and verbal communication skills.
  • Ability to participate confidently in meetings and explain technical work to both technical and nontechnical stakeholders. Preferred Qualifications

  • Experience with Databricks and/or Snowflake.
  • Experience with SIEM platforms and SIEM architecture.
  • Experience with Cribl Stream, Cribl Edge, or other Cribl products.
  • Familiarity with OCSF or other cybersecurity data schemas.
  • Understanding of frameworks and data models such as NIST, MITRE ATT&CK, or the CIM Object Model.
  • Experience working with endpoint, cloud, application, infrastructure, or network security data.
  • Knowledge of Windows, macOS, Linux, and Unix operating systems.
  • Relevant Cribl, cloud, security, or data engineering certifications.
  • Experience supporting security operations or SOAR environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · World Congress 2024

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all