Logo for Air InfoSec

Security Data Engineer (Cribl)

Role overview

Qualifications

  • Hands-on Cribl data modeling experience
  • Strong understanding of enterprise security architecture and engineering principles
  • Experience developing automation and integrations using Python and/or Bash
  • 5 years of experience supporting large IT environments and/or enterprise system deployments

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry
  • Support SIEM administration, analysis, and reporting
  • Troubleshoot complex security-data and integration issues

Key facts

Hard skills

Other skills

  • Microsoft Windows
  • Collaboration
  • Problem Solving
  • Incident Reporting

About the company

Air InfoSec logo

Air InfoSec

Cybersecurity

Air InfoSec is an Austin, Texas based cybersecurity consulting and staffing firm specialized in pairing military veterans, veteran spouses, and transitioning service members with government agency employment opportunities. Air InfoSec can identify and deliver process improvements and meaningful savings within cybersecurity. We often look for talented individuals to join our team on a remote basis. If you are interested or would like additional information, please contact us.

Company details

IndustryCybersecurity
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines.
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
  • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
  • Support SIEM administration, analysis, and reporting.
  • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
  • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
  • Develop security automation and integrations using Python and Bash.
  • Support threat detection, incident-detection activities, and security-control implementation and validation.
  • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
  • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.

Requirements

Minimum Qualifications - Candidates must meet all minimum qualifications

  • Hands-on Cribl data modeling experience.
  • Cribl log-pipeline design and implementation experience.
  • Strong understanding of enterprise security architecture and engineering principles.
  • Experience implementing and supporting enterprise security tools.
  • Exposure to SIEM technologies.
  • Exposure to XDR technologies.
  • Exposure to vulnerability-management technologies.
  • Exposure to Data Loss Prevention (DLP) technologies.
  • Exposure to endpoint-security technologies.
  • Experience developing automation and integrations using Python and/or Bash.
  • Knowledge of cybersecurity best practices.
  • Threat-detection experience.
  • Defensive-security knowledge.
  • Linux operating-system experience.
  • Windows operating-system experience.
  • System-hardening experience.
  • Security-configuration experience.
  • Understanding of networking concepts.
  • Understanding of security protocols.
  • Understanding of secure-system design.
  • 5 years of experience supporting large IT environments and/or enterprise system deployments.
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.

Preferred Qualifications

  • Advanced Cribl Stream experience.
  • SIEM administration experience.
  • SIEM analysis experience.
  • SIEM reporting experience.
  • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
  • Experience building and deploying Linux-based security sensors.
  • Enterprise cybersecurity engineering experience.
  • Security architecture experience.
  • Security automation experience.
  • Security-system integration experience.
  • Knowledge of the NIST Cybersecurity Framework (NIST CSF).
  • Knowledge of CJIS requirements.
  • Knowledge of IRS Publication 1075.
  • Knowledge of CMS MARS-E.
  • CISSP certification.
  • Security+ certification.
  • Location in or near South Carolina with the ability to occasionally report onsite.

Additional Requirements

  • Successful completion of a 7-year standard criminal background check.
  • Successful completion of a full credit-history check.
  • Successful completion of a driving-record (MVR) check.
  • Successful completion of a 10-panel drug screen.
  • E-Verify employment eligibility verification.
  • Successful completion of a SLED check.
  • Ability to obtain and maintain annual CJIS certification.
  • Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate.
  • Participation in an on-call roster.
Work Location and Schedule

Location: Remote within the United States (agency located at 4430 Broad River Road, Columbia, South Carolina 29210).
Schedule: Day schedule, 40 hours per week, with on-call roster participation.
Work Arrangement: 100% remote, with occasional onsite work in South Carolina if requested.


All required experience should be clearly and explicitly documented in the resume.


Salary: $65 - $75/hr.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Data Engineer Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.