Senior Cyber Tech Engineer (Specialist - Data Sciences)
Irving - Texas - USAOn-siteFull-timeData & Analytics
Description
Title: Cyber Tech Engineer Location: Irving, Tx (Hybrid) This role requires a senior BFT Cyber Tech Engineer with deep hands-on expertise in modern cloudnative security platform engineering spanning SIEM data pipeline data lake and SOAR technologies The consultant will be a critical technical contributor in delivering a Unified AIDriven SOC capability a federated broadcapability query and orchestration system that unifies SOC operations threat intelligence log management incident case management and broader security data underpinned by a configurable AI agent layer for incident and event investigation Key Responsibilities · Cloud Native SIEM Engineering · Architect deploy and operate modern cloudnative SIEM platforms eg Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent at enterprise scale · Design and implement federated query capabilities enabling broad crossdomain search across SOC intelligence log management and case management data sources
·� Develop and maintain detection content correlation rules and dashboards aligned to SOC operational requirements and threat use cases
·� Optimize SIEM performance data tiering and retention strategies to balance cost coverage and query fidelity
· Data Pipeline Engineering Cribl · Design build and manage enterprisegrade data pipelines using Cribl Stream andor Cribl Edge for log routing enrichment transformation filtering and normalization at scale · Implement Criblbased data management strategies to optimize data volume reduce ingest costs and ensure highfidelity event delivery to SIEM and data lake destinations · Develop Cribl pipelines that support multidestination routing across SIEM data lake and cold storage tiers · Collaborate with detection engineering and threat intelligence teams to enrich pipeline data with contextual security signals ·� Security Data Lake Engineering
·� Architect and manage a scalable cloudnative security data lake eg on AWS S3Athena GCP BigQuery or Snowflake for long-term log retention threat hunting and AIML workloads
· Develop data models schemas and partitioning strategies optimized for security analytics and federated query performance · Enable broadcapability query access across SOC intel and incident data stored within the data lake supporting both real-time and retrospective investigation workflows · Integrate data lake telemetry with SIEM and SOAR platforms to support unified investigation and orchestration · SOAR Platform Engineering · Design deploy and maintain SOAR platform infrastructure eg Palo Alto XSOAR Splunk SOAR Google Sec Ops SOAR or equivalent to enable automated incident response and orchestration workflows · Build and maintain SOAR playbooks and integrations that span SOC case management threat intelligence SIEM ing and external security tooling · Engineer orchestration workflows that leverage AI agent capabilities for automated event triage enrichment and investigation recommendations · Continuously improve SOAR operational efficiency through playbook tuning integration maintenance and metricdriven optimization
·� AIDriven SOC Enablement
·� Contribute to the design and implementation of a configurable AI agent layer for incident and event investigation integrating with SIEM SOAR data lake and case management systems · Engineer the data and API connectivity required to support AI agent queries context retrieval and automated investigation workflows across federated SOC data sources · Collaborate with data science AIML engineering and detection engineering teams to operationalize AIdriven investigation and triage capabilities within the SOC platform · Support the evaluation and integration of emerging AIGen AI security operations tooling aligned to the unified SOC vision · Platform Integration Federated Architecture · Design and implement integration patterns that connect SIEM data pipeline data lake SOAR and case management platforms into a cohesive federated SOC data fabric · Develop and maintain APIs webhooks and data connectors to ensure seamless interoperability across the SOC technology ecosystem · Apply cloudnative engineering best practices IaC CICD containerization to SOC platform deployment configuration management and operational scaling
Required Skills Experience
·� Experience 7 years in cybersecurity or security platform engineering with demonstrable hands-on experience across SIEM data pipeline data lake and SOAR technologies in enterprise environments
·� SIEM
· Deep expertise in one or more modern cloudnative SIEM platforms Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent · Experience with federated search data normalization eg UDM OCSF and largescale detection content management · Data Pipeline Cribl Required · Strong hands-on proficiency with Cribl Stream andor Cribl Edge for enterprise log management routing enrichment and transformation · Experience designing multidestination Cribl pipelines across SIEM data la
Requirements
Mandatory Skills : Python-Cybersecurity