Senior Platform Operations Engineer

State Street
Atlanta, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Atlanta, United States of America

Tech stack

Artificial Intelligence
Amazon Web Services (AWS)
Confluence
JIRA
Cloud Computing
Cloud Engineering
Cluster Analysis
Computer Security
Data Retention
Linux
Elasticsearch
Intrusion Detection and Prevention
Python
Security Information and Event Management
Scripting (Bash/Python/Go/Ruby)
Cloud Platform System
Data Ingestion
System Availability
QRadar
Technical Debt
Indexer
Data Lake
Data Analytics
Enterprise Integration
Data Management
Splunk
Software Version Control
Data Pipelines
ServiceNow
Databricks

Job description

Experteer Overview In this role you will help shape the next generation of cybersecurity data, analytics, and AI-powered platforms. You will lead and support globally distributed teams responsible for enterprise SIEM, observability, and data platforms, ensuring high availability and reliable operations. You will drive platform modernization, incident response, and operational excellence across security technologies. This is an opportunity to impact threat detection and response at scale within a leading financial services firm. Compensation / Benefits * Lead the day-to-day operations and reliability of enterprise cybersecurity platforms and SIEM technologies * Support the operational roadmap for SIEM, observability, log management, and data ingestion across the organization * Drive platform modernization and operational improvements across cybersecurity platforms and tooling * Provide technical leadership and mentorship to global support teams for SIEM, observability, data pipelines, and analytics capabilities * Manage SIEM components (search, indexing, clustering, data management) and platform integrations across Splunk, Elastic Search, and related tools * Administer and optimize SIEM and security operations to support threat detection, alert triage, and incident investigation * Improve platform reliability using monitoring, metrics, and operational insights; reduce issues and technical debt * Lead upgrades, migrations, and service improvement programs; coordinate change activities and ensure SOP adherence * Support data telemetry pipelines and Cribl monitoring; validate service health and coordinate with cross-functional teams * Ensure Databricks Data Lake integration for analytics and long-term data retention * Monitor ingestion health, data quality, storage utilization, and platform availability across SIEM, log management, and data platforms * Collaborate with Cyber Security, Infrastructure, Cloud Engineering, and Service Management teams to resolve production issues * Hands-on experience with Anvilogic and Crogl (Crogl) or similar SIEM detection platforms for detection engineering and alert workflows * Lead incident response, root cause analysis, and continuous improvement activities * Define and improve operational standards, governance, documentation, and SOPs aligned to ITIL and change management * Ensure compliance with security, audit, regulatory, and data lifecycle requirements * Mentor engineers, coordinate global teams, manage vendor engagement, and contribute to strategic technology planning Tasks * Experience administering enterprise SIEM, cybersecurity, observability, and log management platforms (Splunk, QRadar, Elastic) * Deep SIEM concepts: threat detection, incident response, correlation searches, data models, risk-based alerting * Log management, monitoring, operational analytics, and data onboarding frameworks * Cribl Stream for data routing, transformation, and optimization * Databricks Data Lake integration and data pipeline management * Cloud experience (preferably AWS) and Linux/Unix administration * Scripting/automation (Python/Shell) and version control practices * Familiarity with ServiceNow, Jira, Confluence for incident/problem/change management and documentation * ITIL processes and operational best practices; compliance and data lifecycle awareness * Strong communication and collaboration across global teams and time zones * 10+ years in technology infrastructure/platform engineering/security operations * 5+ years of technical leadership in a large enterprise * Relevant certifications (AWS, Splunk, ITIL, CISSP) preferred Key requirements * 401K with company match * comprehensive insurance coverage (medical, dental, vision, life, disability) * paid time off and family care benefits * Employee Assistance Program * annual performance-based incentive eligibility * volunteer days and flexible work-life support

Requirements

  • Hands-on experience with Anvilogic and Crogl (Crogl) or similar SIEM detection platforms for detection engineering and alert workflows * Lead incident response, root cause analysis, and continuous improvement activities * Define and improve operational standards, governance, documentation, and SOPs aligned to ITIL and change management * Ensure compliance with security, audit, regulatory, and data lifecycle requirements * Mentor engineers, coordinate global teams, manage vendor engagement, and contribute to strategic technology planning Tasks * Experience administering enterprise SIEM, cybersecurity, observability, and log management platforms (Splunk, QRadar, Elastic) * Deep SIEM concepts: threat detection, incident response, correlation searches, data models, risk-based alerting * Log management, monitoring, operational analytics, and data onboarding frameworks * Cribl Stream for data routing, transformation, and optimization * Databricks Data Lake integration and data pipeline aaaaaa with * Cloud experience (preferably AWS) and Linux/Unix administration * Scripting/automation (Python/Shell) and version control practices * Familiarity with ServiceNow, Jira, Confluence for incident/problem/change management and documentation * ITIL processes and operational best practices; compliance and data lifecycle awareness * Strong communication and collaboration across global teams and time zones * 10+ years in technology infrastructure/platform engineering/security operations * 5+ years of technical leadership in a large enterprise * Relevant certifications (AWS, Splunk, ITIL, CISSP) preferred Key requirements * 401K with company match * comprehensive insurance coverage (medical, dental, vision, life, disability) * paid time off and family care benefits * Employee Assistance Program * annual performance-based incentive eligibility * volunteer days and flexible work-life support

Apply for this position