> Markdown version of [/jobs/ext/3427587-senior-cribl-engineer-security-data-engineer](https://www.wearedevelopers.com/jobs/ext/3427587-senior-cribl-engineer-security-data-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cribl Engineer / Security Data Engineer - **Company:** The Sugrue Group Limited Liability Company - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $170,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Amazon Web Services, Data Analysis, ARM Architecture, Cyber Security, Databases, Information Engineering, Data Infrastructure, Data Normalization, Data Security, Data Systems, Software Debugging, Intrusion Detection and Prevention, Python (Programming Language), Security Log, Security Information and Event Management, SQL Stored Procedures, Data Streaming, Systems Integration, Scripting, Data Ingestion, Delivery Pipeline, Snowflake, Data Lakes, Cybercrime, Data Management, Data Pipelines, Databricks - **Published:** September 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=936aa9357e275d33 ## About the Role * 3+ years of experience with Cribl LogStream administration, configuration, and pipeline development. * 2+ years of hands-on experience with Snowflake administration, architecture, and data engineering in large-scale enterprise environments. * Experience designing and supporting large-scale security data ingestion, transformation, and processing pipelines utilizing platforms such as Snowflake and Databricks. * Experience with scripting languages (e.g., Python, JavaScript) for pipeline automation. * Experience onboarding and managing enterprise security data within SIEM, security data lake, or security analytics environments. * Familiarity with OCSF, security data normalization, governance, compliance, and other security telemetry best practices. * Excellent problem-solving skills, ability to debug complex pipeline issues, and strong analytical thinking * Experience designing, creating, and managing Snowflake databases, schemas, tables, views, streams, tasks, stored procedures, and data pipelines * Experience with Snowflake Cortex, Snowpark, Python UDFs, stored procedures, and advanced automation frameworks. ## Description Seeking an experienced Senior Cribl Engineer / Security Data Engineer to develop, maintain, and optimize scalable data pipelines utilizing Cribl LogStream. The ideal candidate should have deep knowledge of Cribl architecture, extensive hands-on experience in data engineering, and the ability to improve data ingestion and processing workflows. Familiarity with security operations, SIEM platforms, the Open Cybersecurity Schema Framework (OCSF), security log data, AWS cloud services, and modern data platforms such as Snowflake and Databricks is highly desirable., * Develop, implement, and maintain data processing pipelines within Cribl LogStream. * Configure and optimize data routing, transformation, enrichment, filtering, normalization, and data quality processes. * Develop and support integrations between Cribl, AWS, SIEM platforms, security analytics tools, and enterprise security lake data platforms. * Build, troubleshoot, and optimize automated data ingestion and onboarding workflows. * Onboard and validate security telemetry for SIEM, detection engineering, threat hunting, incident response, and security analytics use cases. * Collaborate with Security Operations, Detection Engineering, Data Engineering, Infrastructure, and Analytics teams to deliver reliable, scalable, and high-quality data solutions. * Monitor pipeline performance, resolve issues, and implement continuous improvements. * Document pipeline configurations, operational procedures, and data flows. * Develop, create, and maintain Snowflake database objects including databases, schemas, tables, views, streams, tasks, stored procedures, and secure data-sharing configurations.