Senior CyberTech Engineer (Specialist - Data Sciences)
LTM
Title: CyberTech Engineer Location: Irving, Tx (Hybrid)This role requires a senior BFT CyberTech Engineer with deep handson expertise in modern cloudnative security platform engineering spanning SIEM data pipeline data lake and SOAR technologies The consultant will be a critical technical contributor in delivering a Unified AIDriven SOC capability a federated broadcapability query and orchestration system that unifies SOC operations threat intelligence log management incident case management and broader security data underpinned by a configurable AI agent layer for incident and event investigationKey Responsibilities· Cloud Native SIEM Engineering· Architect deploy and operate modern cloudnative SIEM platforms eg Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent at enterprise scale· Design and implement federated query capabilities enabling broad crossdomain search across SOC intelligence log management and case management data sources· Develop and maintain detection content correlation rules and dashboards aligned to SOC operational requirements and threat use cases· Optimize SIEM performance data tiering and retention strategies to balance cost coverage and query fidelity· Data Pipeline Engineering Cribl· Design build and manage enterprisegrade data pipelines using Cribl Stream andor Cribl Edge for log routing enrichment transformation filtering and normalization at scale· Implement Criblbased data management strategies to optimize data volume reduce ingest costs and ensure highfidelity event delivery to SIEM and data lake destinations· Develop Cribl pipelines that support multidestination routing across SIEM data lake and cold storage tiers· Collaborate with detection engineering and threat intelligence teams to enrich pipeline data with contextual security signals· Security Data Lake Engineering· Architect and manage a scalable cloudnative security data lake eg on AWS S3Athena GCP BigQuery or Snowflake for longterm log retention threat hunting and AIML workloads· Develop data models schemas and partitioning strategies optimized for security analytics and federated query performance· Enable broadcapability query access across SOC intel and incident data stored within the data lake supporting both realtime and retrospective investigation workflows· Integrate data lake telemetry with SIEM and SOAR platforms to support unified investigation and orchestration· SOAR Platform Engineering· Design deploy and maintain SOAR platform infrastructure eg Palo Alto XSOAR Splunk SOAR Google SecOps SOAR or equivalent to enable automated incident response and orchestration workflows· Build and maintain SOAR playbooks and integrations that span SOC case management threat intelligence SIEM ing and external security tooling· Engineer orchestration workflows that leverage AI agent capabilities for automated event triage enrichment and investigation recommendations· Continuously improve SOAR operational efficiency through playbook tuning integration maintenance and metricdriven optimization· AIDriven SOC Enablement· Contribute to the design and implementation of a configurable AI agent layer for incident and event investigation integrating with SIEM SOAR data lake and case management systems· Engineer the data and API connectivity required to support AI agent queries context retrieval and automated investigation workflows across federated SOC data sources· Collaborate with data science AIML engineering and detection engineering teams to operationalize AIdriven investigation and triage capabilities within the SOC platform· Support the evaluation and integration of emerging AIGenAI security operations tooling aligned to the unified SOC vision· Platform Integration Federated Architecture· Design and implement integration patterns that connect SIEM data pipeline data lake SOAR and case management platforms into a cohesive federated SOC data fabric· Develop and maintain APIs webhooks and data connectors to ensure seamless interoperability across the SOC technology ecosystem· Apply cloudnative engineering best practices IaC CICD containerization to SOC platform deployment configuration management and operational scalingRequired Skills Experience· Experience 7 years in cybersecurity or security platform engineering with demonstrable handson experience across SIEM data pipeline data lake and SOAR technologies in enterprise environments· SIEM· Deep expertise in one or more modern cloudnative SIEM platforms Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent· Experience with federated search data normalization eg UDM OCSF and largescale detection content management· Data Pipeline Cribl Required· Strong handson proficiency with Cribl Stream andor Cribl Edge for enterprise log management routing enrichment and transformation· Experience designing multidestination Cribl pipelines across SIEM data la
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior CyberTech Engineer (Specialist - Data Sciences). Be the first to apply!
- aws data engineer Irving, TX
- data engineer machine learning Irving, TX
- data science developer Irving, TX
- senior data engineer Irving, TX
- finance data engineer Irving, TX
- big data devops engineer Irving, TX
- data engineer analytics Irving, TX
- senior data integration developer Irving, TX
- junior data engineer remote Irving, TX
- data center engineer Irving, TX
