Security Architect Consultant Data Modeling Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+24 more
Job description
Design, build, implement, and maintain Cribl data models and log pipelines
Develop enterprise security-data ingestion and routing workflows
Configure pipelines that deliver security telemetry into enterprise SIEM environments
Perform data parsing, filtering, transformation, enrichment, routing, and normalization
Work directly with enterprise security architects and engineers
Support SIEM administration, analysis, and reporting
Implement and support enterprise security technologies
Support XDR platforms
Support vulnerability-management technologies
Support DLP technologies
Support endpoint-security platforms
Build and deploy Linux-based security sensors
Support Linux and Windows security configuration and hardening
Develop security automation and integrations using Python and Bash
Support enterprise threat-detection capabilities
Assist with defensive-security engineering
Support security-control implementation and validation
Participate in enterprise security architecture discussions
Support incident-detection activities
Troubleshoot complex security-data and integration issues
Support secure networking and system-design initiatives
Participate in the required on-call rotation
Requirements
Do not move forward with a candidate unless the required hands-on Cribl experience, enterprise security engineering experience, SIEM experience, Python/Bash scripting, operating-system security experience, rate expectations, screening requirements, education/experience requirements, work-location requirements, and required submission documents have been confirmed., * The State of South Carolina is seeking an experienced Security Architect Consultant Data Modeling Engineer with deep hands-on experience using Cribl to design, implement, and maintain enterprise security-data pipelines.
- This is not a general cybersecurity architect or SIEM administrator position.
- The central requirement is hands-on experience with Cribl data modeling, log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments.
- The selected consultant will work alongside full-time security architects and engineers supporting large-scale enterprise cybersecurity initiatives.
- The role combines Cribl engineering with broader hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, Linux security sensors, Windows/Linux security configuration, security integrations, automation, threat detection, and defensive security architecture.
- Automation is also important. Candidates should demonstrate experience building integrations and security automation using scripting languages such as Python and Bash.
- The strongest candidates will have substantial experience operating within complex enterprise security environments rather than simply having exposure to Cribl or SIEM technologies.
Scope of Project
The selected consultant will support:
Cribl data modeling
Cribl Stream / log-pipeline architecture
Enterprise log ingestion
Security-data routing
Parsing and transformation of security telemetry
Data normalization and enrichment
SIEM data delivery and integration
SIEM administration, analysis, and reporting
Enterprise security architecture
Security-tool implementation and support
XDR technologies
Vulnerability-management platforms
Data Loss Prevention / DLP
Endpoint security
Linux-based security sensors
Windows and Linux security configuration
Security-system hardening
Cybersecurity automation
Python scripting
Bash scripting
Security integrations
Threat detection
Defensive security strategies
Networking and secure-system design
Security controls and countermeasures
Security-control validation, The candidate must have:
Hands-on Cribl data modeling experience
Cribl log-pipeline design and implementation experience
Strong understanding of enterprise security architecture and engineering principles
Experience implementing and supporting enterprise security tools
Security-tool experience should include exposure to technologies such as:
SIEM
XDR
Vulnerability Management
Data Loss Prevention / DLP
Endpoint Security
The candidate must also have:
Experience developing automation and integrations using Python and/or Bash
Knowledge of cybersecurity best practices
Threat-detection experience
Defensive-security knowledge
Linux operating-system experience
Windows operating-system experience
System-hardening experience
Security-configuration experience
Understanding of networking concepts
Understanding of security protocols
Understanding of secure-system design
5+ years of experience supporting large IT environments and/or enterprise system deployments
All required experience should be clearly and explicitly documented in the resume.
Do not rely solely on a skills section or broad statements such as, For Cribl specifically, the resume should demonstrate meaningful hands-on responsibility rather than simple platform exposure.
Required Education
The candidate should have:
Bachelor’s degree in an Information Technology-related field
OR
Bachelor’s degree in a Security-related field
OR
8+ years of relevant professional experience may be substituted in lieu of the degree requirement
Please confirm the candidate’s education and/or qualifying equivalent experience before submission.
Preferred Qualifications
Preferred experience includes:
Hands-on Cribl data modeling experience
Advanced Cribl Stream experience
SIEM administration
SIEM analysis
SIEM reporting
Building and deploying Linux-based security sensors
Enterprise cybersecurity engineering
Security architecture
Security automation
Security-system integration
NIST Cybersecurity Framework / NIST CSF, The strongest candidates will demonstrate multiple preferred qualifications, but hands-on Cribl remains the most important technical signal.
Additional Skills
The candidate should also demonstrate:
Strong enterprise security-engineering capabilities
Strong troubleshooting and analytical skills
Strong technical communication skills
Ability to work with security architects and engineering teams
Ability to design scalable security-data pipelines
Ability to troubleshoot log-ingestion and routing issues
Ability to automate repetitive security-engineering processes
Ability to understand complex security-data flows
Strong Linux skills
Strong Windows-security knowledge
Strong networking fundamentals
Ability to work independently in a remote environment
Ability to participate in an on-call environment, 5+ years of enterprise IT/security experience
Real hands-on Cribl Stream experience
Cribl data modeling experience
Cribl pipeline-design experience
Log-ingestion experience
Log-routing experience
Parsing and transformation experience
Data normalization experience
Security telemetry experience
Enterprise SIEM experience
SIEM administration or engineering experience
Python scripting experience
Bash scripting experience
Linux security experience
Windows security experience
Security automation experience
Security-tool integration experience
XDR experience
Vulnerability-management experience
DLP experience
Endpoint-security experience
Networking/security-protocol knowledge
Threat-detection experience
Defensive-security experience
Experience supporting large enterprise environments
Especially strong profiles may combine Cribl with SIEM platforms such as:
Splunk
Microsoft Sentinel
IBM QRadar
Elastic / Elasticsearch
Other large-scale enterprise SIEM platforms
Cribl Screening Standard, Built integrations between security-data sources and SIEM platforms
Troubleshot Cribl pipeline failures or data-flow issues
Supported Cribl in a production enterprise environment
Candidates should be able to explain their Cribl architecture, data sources, destinations, transformations, routing logic, and SIEM integrations in detail.
Avoid candidates whose backgrounds are primarily focused on:
General cybersecurity with no Cribl experience
SIEM administration with no Cribl experience
Splunk administration without Cribl pipeline engineering, Candidates without meaningful Python or Bash scripting experience
Candidates without enterprise security-tool experience
Candidates without Linux and Windows experience, Ability to work directly on CornerStone’s W-2, when required, Ability to work remotely within the United States, Hands-on Cribl experience
Cribl data modeling experience
Cribl log-pipeline design experience
Cribl implementation experience
Enterprise SIEM experience
Enterprise security architecture or engineering experience
XDR experience, when applicable
Vulnerability-management experience, when applicable
DLP experience, when applicable
Endpoint-security experience
Python scripting experience
Bash scripting experience
Linux experience
Windows experience
System-hardening/security-configuration experience
Networking knowledge
Security-protocol knowledge
Secure-system-design knowledge
Threat-detection experience
Defensive-security experience
At least 5 years supporting large IT environments and/or enterprise system deployments
Preferred experience should also be confirmed when applicable:
Hands-on SIEM administration
SIEM analysis
SIEM reporting
Linux-based security-sensor deployment
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Quick guide: How to write a Software Developer CV
Résumé-Driven Development: How IT trends affect the job market for software developers
How to Write a CV and Interview if You Don't Fully Qualify For The Job
Why Upskilling And Reskilling is Important For Developers