Data Platform Engineer, Cybersecurity Operations
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+26 more
Job description
We are seeking a Data Platform Engineer with deep, specialized expertise in data platform architecture and engineering to build and operate the scalable data pipelines, storage backbones, and data lakes that power our next-generation cybersecurity operations capabilities. This role sits at the foundation of our security analytics capability, ingesting and normalizing massive volumes of SOC telemetry into modern, high-performance analytics platforms., * Pipeline Engineering: Design, build, and operate scalable, resilient, high-throughput data pipelines (batch and streaming) that ingest security relevant telemetry - logs, alerts, network flow data, endpoint events, identity signals, and cloud events - from across the enterprise.
- Data Normalization: Develop robust normalization and enrichment logic to transform heterogeneous SOC telemetry formats into standardized schemas consumable by downstream analytics and detection platforms.
- Storage Backbone Architecture: Architect and maintain the storage backbone (data lakes, warehouses, streaming stores) that serves as the durable, queryable source of truth for SOC data at enterprise scale.
- Data Lake Operations: Build and operate data lake infrastructure optimized for high-volume security telemetry, balancing cost, performance, retention, and query flexibility.
- Integration with Analytics Platforms: Ensure seamless, low-latency delivery of normalized SOC data into modern analytics platforms, SIEM/XDR tooling, and other downstream systems.
- Scalability & Performance Engineering: Continuously tune pipeline throughput, storage partitioning, and query performance to keep pace with growing telemetry volume and evolving analytics demands.
- Reliability & Observability: Implement monitoring, alerting, and self-healing capabilities to ensure pipeline uptime, data completeness, and data quality at production scale.
- Schema & Taxonomy Governance: Define and enforce data schemas, taxonomies, and metadata standards across ingested telemetry sources to enable consistent downstream consumption.
- Automation of Onboarding: Build reusable frameworks and automation to rapidly onboard new telemetry sources as the tool and sensor ecosystem expands.
- Security & Compliance: Ensure secure handling, encryption, access control, and regulatory compliance for sensitive security data throughout its lifecycle (ingestion, storage, processing, access).
- Cross-Functional Collaboration: Partner closely with cybersecurity operations analysts, detection engineers, threat and exposure management teams, and data science teams to ensure the platform meets operational and analytical needs.
- Documentation & Knowledge Transfer: Maintain clear architecture documentation, data dictionaries, and operational runbooks to support platform sustainability and team scalability. *
Requirements
- Deep, demonstrable expertise in data platform architecture and engineering - a proven track record of architecting and operating large-scale, mission-critical data platforms from the ground up, with strong judgment on trade-offs across scalability, cost, performance, and reliability.
- Extensive, hands-on experience building and operating large-scale data pipelines (batch and streaming) using technologies such as Cribl, Kafka, Spark, Flink, Airflow, or equivalent.
- Deep expertise in data lake and data warehouse architecture (e.g., Delta Lake, Iceberg, Snowflake, BigQuery, Redshift) at enterprise scale, including experience making foundational design decisions on storage formats, partitioning strategies, and query engines.
- Proven, in-depth experience with cloud-native data infrastructure (AWS/Azure/GCP), including storage tiering, cost optimization, and event-driven architectures.
- Strong understanding of security telemetry types - logs, network flow, endpoint/EDR data, identity events, cloud audit logs - and the architectural challenges of ingesting and normalizing them at scale.
- Advanced proficiency in a major programming language (Python, Go, Java, or Scala) for pipeline development and automation.
- Deep experience with schema design, data modeling, and metadata management for large, heterogeneous, high-velocity datasets.
- Solid grounding in cybersecurity fundamentals, particularly SOC/OSVM operations, log management, and detection/analytics use cases.
- Extensive experience with database technologies spanning relational, NoSQL, time-series, and columnar/analytical stores.
- Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, automated testing, and observability/monitoring practices.
- Demonstrated ability to architect for scale and reliability in mission-critical, 24x7 operational environments.
- Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and data science teams., * 10+ years of experience in architecting data platforms specifically for SOC, SIEM, or XDR environments.
- Familiarity with AI/ML pipeline requirements (feature stores, training data pipelines) to support advanced security analytics.
- Deep experience with open table formats (Iceberg, Delta Lake, Hudi) and modern lakehouse architectures.
- Relevant certifications (e.g., cloud data engineering certifications, GIAC) are a plus but not required in lieu of hands-on expertise., A platform architect and builder at heart - someone who has spent their career deep in data platform engineering and wants to apply that expertise to one of the highest-stakes data domains in the enterprise: security telemetry at scale. You should be equally comfortable leading architectural / system design discussions and rolling up your sleeves to build and operate production systems., * Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred
Benefits & conditions
$156,160.00 - $234,240.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
About the company
Working at Citi is far more than just a job. A career with us means joining a team of approximately 219,000 dedicated people from around the globe. At Citi, you’ll have the opportunity to grow your career, give back to your community and make a real impact.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Making Data Warehouses Fast: A Developer’s Story
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Highest Paying Tech Companies for Developers
Top Big Data Technologies That You Need to Know