Security Data Engineer (Cribl)
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 29, 2026
Job Description
This is a remote position.
The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.
Responsibilities
- Design, build, implement, and maintain Cribl data models and log pipelines.
- Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
- Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
- Support SIEM administration, analysis, and reporting.
- Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
- Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
- Develop security automation and integrations using Python and Bash.
- Support threat detection, incident-detection activities, and security-control implementation and validation.
- Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
- Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.
Requirements
Minimum Qualifications - Candidates must meet all minimum qualifications
- Hands-on Cribl data modeling experience.
- Cribl log-pipeline design and implementation experience.
- Strong understanding of enterprise security architecture and engineering principles.
- Experience implementing and supporting enterprise security tools.
- Exposure to SIEM technologies.
- Exposure to XDR technologies.
- Exposure to vulnerability-management technologies.
- Exposure to Data Loss Prevention (DLP) technologies.
- Exposure to endpoint-security technologies.
- Experience developing automation and integrations using Python and/or Bash.
- Knowledge of cybersecurity best practices.
- Threat-detection experience.
- Defensive-security knowledge.
- Linux operating-system experience.
- Windows operating-system experience.
- System-hardening experience.
- Security-configuration experience.
- Understanding of networking concepts.
- Understanding of security protocols.
- Understanding of secure-system design.
- 5 years of experience supporting large IT environments and/or enterprise system deployments.
- Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.
Preferred Qualifications
- Advanced Cribl Stream experience.
- SIEM administration experience.
- SIEM analysis experience.
- SIEM reporting experience.
- Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
- Experience building and deploying Linux-based security sensors.
- Enterprise cybersecurity engineering experience.
- Security architecture experience.
- Security automation experience.
- Security-system integration experience.
- Knowledge of the NIST Cybersecurity Framework (NIST CSF).
- Knowledge of CJIS requirements.
- Knowledge of IRS Publication 1075.
- Knowledge of CMS MARS-E.
- CISSP certification.
- Security+ certification.
- Location in or near South Carolina with the ability to occasionally report onsite.
Additional Requirements
- Successful completion of a 7-year standard criminal background check.
- Successful completion of a full credit-history check.
- Successful completion of a driving-record (MVR) check.
- Successful completion of a 10-panel drug screen.
- E-Verify employment eligibility verification.
- Successful completion of a SLED check.
- Ability to obtain and maintain annual CJIS certification.
- Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate.
- Participation in an on-call roster.