Air InfoSec, LLC Logo

Air InfoSec, LLC

Security Data Engineer (Cribl)

Posted 2 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Designs and maintains Cribl data models and security log pipelines, routing and transforming telemetry into enterprise SIEM platforms. Supports SIEM, XDR, vulnerability management, DLP, endpoint security, Linux sensors, system hardening, threat detection, and defensive security architecture. Develops Python and Bash automation, integrations, and security controls while troubleshooting complex data issues. The role is fully remote within the United States, includes occasional South Carolina onsite work, and requires on-call participation.
The summary above was generated by AI

This is a remote position.

The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines.
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
  • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
  • Support SIEM administration, analysis, and reporting.
  • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
  • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
  • Develop security automation and integrations using Python and Bash.
  • Support threat detection, incident-detection activities, and security-control implementation and validation.
  • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
  • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.

Requirements

Minimum Qualifications - Candidates must meet all minimum qualifications

  • Hands-on Cribl data modeling experience.
  • Cribl log-pipeline design and implementation experience.
  • Strong understanding of enterprise security architecture and engineering principles.
  • Experience implementing and supporting enterprise security tools.
  • Exposure to SIEM technologies.
  • Exposure to XDR technologies.
  • Exposure to vulnerability-management technologies.
  • Exposure to Data Loss Prevention (DLP) technologies.
  • Exposure to endpoint-security technologies.
  • Experience developing automation and integrations using Python and/or Bash.
  • Knowledge of cybersecurity best practices.
  • Threat-detection experience.
  • Defensive-security knowledge.
  • Linux operating-system experience.
  • Windows operating-system experience.
  • System-hardening experience.
  • Security-configuration experience.
  • Understanding of networking concepts.
  • Understanding of security protocols.
  • Understanding of secure-system design.
  • 5 years of experience supporting large IT environments and/or enterprise system deployments.
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.

Preferred Qualifications

  • Advanced Cribl Stream experience.
  • SIEM administration experience.
  • SIEM analysis experience.
  • SIEM reporting experience.
  • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
  • Experience building and deploying Linux-based security sensors.
  • Enterprise cybersecurity engineering experience.
  • Security architecture experience.
  • Security automation experience.
  • Security-system integration experience.
  • Knowledge of the NIST Cybersecurity Framework (NIST CSF).
  • Knowledge of CJIS requirements.
  • Knowledge of IRS Publication 1075.
  • Knowledge of CMS MARS-E.
  • CISSP certification.
  • Security+ certification.
  • Location in or near South Carolina with the ability to occasionally report onsite.

Additional Requirements

  • Successful completion of a 7-year standard criminal background check.
  • Successful completion of a full credit-history check.
  • Successful completion of a driving-record (MVR) check.
  • Successful completion of a 10-panel drug screen.
  • E-Verify employment eligibility verification.
  • Successful completion of a SLED check.
  • Ability to obtain and maintain annual CJIS certification.
  • Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate.
  • Participation in an on-call roster.
Work Location and Schedule

Location: Remote within the United States (agency located at 4430 Broad River Road, Columbia, South Carolina 29210).
Schedule: Day schedule, 40 hours per week, with on-call roster participation.
Work Arrangement: 100% remote, with occasional onsite work in South Carolina if requested.


All required experience should be clearly and explicitly documented in the resume.




Similar Jobs

39 Minutes Ago
Remote or Hybrid
Oregon, USA
Mid level
Mid level
Digital Media • Information Technology • News + Entertainment
Develop and manage local advertising clients and agencies to achieve sales goals. Create market research, advertising proposals, forecasts, reports, and sales documentation. Prospect for new customers, coordinate advertising schedules and client requirements with internal teams, monitor account activity and collections, and maintain accurate customer records. The role requires independent judgment, punctual attendance, and flexibility to work nights, weekends, variable schedules, and overtime.
Top Skills: Advertising TechnologyDigital AdvertisingMultiscreen Video AdvertisingTv Advertising
40 Minutes Ago
Remote or Hybrid
Illinois, USA
102K-161K Annually
Senior level
102K-161K Annually
Senior level
Digital Media • Information Technology • News + Entertainment
Designs and implements complex enterprise network solutions, supports customer pilots and sales, provides Tier IV escalation support, troubleshoots network issues, develops capacity models, evaluates hardware and software, maintains technical documentation and procedures, and conducts security audits. Leads and mentors network engineers, presents technical information, participates in an on-call rotation, and supports customer professional services projects. The role requires independent judgment, occasional travel, and variable night or weekend work.
Top Skills: AaaAclsAerohiveBgpCiscoCisco Catalyst Sd-WanCisco CceCisco FirepowerCisco MerakiCisco PrimeCradlepointDhcpDmvpnEigrpFortianalyzerFortimanagerFortinet FortigateGlbpGreHipaaHsrpIpsecIwanJuniperMistNetscoutOspfPci DssPolicy RoutingPriQosRadiusRipSd-WanSipSnmpSocSolarwinds OrionStpTacacs+VlansVoipVrrpVtpWhatsup GoldWireless NetworkingWireshark
40 Minutes Ago
Easy Apply
Remote or Hybrid
Easy Apply
172K-245K Annually
Expert/Leader
172K-245K Annually
Expert/Leader
Cloud • Information Technology • Security • Software • Cybersecurity
Conduct advanced threat research across endpoint and cloud environments, dissecting and replicating adversary techniques to improve detection. Engineer attack automation, test code, and proof-of-concept detections; collaborate with detection engineers, analysts, and threat hunters; document findings; influence product strategy and vendor telemetry; and mentor junior researchers.
Top Skills: Ai/MlAWSCC++Endpoint Detection And Response (Edr)GitGitGoLinuxmacOSMicrosoft 365OktaPowershellPythonRustWindows

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account