Security Observability Engineer
Indexed description
Key Responsibilities
- End-to-End SIEM Pipeline Management & Optimization
- Lead the migration of log sources from Splunk ingestion to Cribl Stream/Edge
- Architect and manage scalable, resilient pipelines—including design,
- Analyze, tune and securely onboard all log sources (firewalls, EDR, cloud,
- Develop and maintain Cribl and Splunk configurations, including advanced
- Ensure optimal distribution of logging workload across Cribl worker nodes and
- Security Event Visibility and SOC Enablement
- Collaborate with SOC, IR, and threat detection teams to ensure all security logs
- Actively monitor, test, and remediate pipeline balancing and ingestion health to
- Respond to and resolve SIEM and pipeline issues that impact security, detection, or
- Governance, Compliance & Documentation
- Apply and document security policies for log routing, load balancing, event
- Track and report ingest reduction, Splunk cost savings, pipeline health, and event
- Maintain clear, up-to-date documentation of log flows, pipeline topology, load
Required Skills & Qualifications
- Extensive hands-on experience with Splunk SIEM engineering (indexers, search
- 2+ years with Cribl Stream/Edge, including deployment and tuning of distributed,
- Deep understanding of machine data transport (syslog, HEC, TCP, UDP), log
- Proven expertise onboarding, parsing, and tuning security log sources (firewalls,
- Advanced Splunk SPL, data model, event parsing, and alert tuning skills; practical
- Scripting/automation ability (Python, shell/CLI, or similar) for pipeline management
- Strong troubleshooting, monitoring, and operational dashboard skills for both
Preferred Qualifications
- Hands-on experience designing and operating clustered/HA Cribl and Splunk
- Splunk ES or Cribl certifications.
- No loss of security data or alert coverage during/after pipeline migration and
- Documented, measurable reductions in Splunk ingest volume and
- Consistently balanced log throughput and minimal risk of bottlenecks or
- Well-documented, adaptable pipeline and load balancing architecture.
Starr is an equal opportunity employer, which means we'll consider all suitably qualified applicants regardless of gender identity or expression, ethnic origin, nationality, religion or beliefs, age, sexual orientation, disability status or any other protected characteristic. We recruit and develop our people based on merit and we're committed to creating an inclusive environment for all employees. We offer first class training and development opportunities to all employees. Our aim is to grow our own talent and bring out the best in people.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search