Air InfoSec, LLC

Security Data Engineer (Cribl)

United States · REMOTE · FREELANCE
Publiée le 2 octobre 2026 · Candidature traitée sur le site de l’entreprise
DeveloperSecurity-Software-Data-EngineerCybersecurity-EngineerSIEM-EngineerSecurity-EngineerSOC-EngineerData-Security-EngineerSecurity-Data-EngineeringSenior-Security-Data-Infrastructure-EngineerSecurity-Analytics-Engineer

This is a remote position. The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture. Responsibilities • Design, build, implement, and maintain Cribl data models and log pipelines. • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments. • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry. • Support SIEM administration, analysis, and reporting. • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms. • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening. • Develop security automation and integrations using Python and Bash. • Support threat detection, incident-detection activities, and security-control implementation and validation. • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives. • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation. Requirements Minimum Qualifications - Candidates must meet all minimum qualifications • Hands-on Cribl data modeling experience. • Cribl log-pipeline design and implementation experience. • Strong understanding of enterprise security architecture and engineering principles. • Experience implementing and supporting enterprise security tools. • Exposure to SIEM technologies. • Exposure to XDR technologies. • Exposure to vulnerability-management technologies. • Exposure to Data Loss Prevention (DLP) technologies. • Exposure to endpoint-security technologies. • Experience developing automation and integrations using Python and/or Bash. • Knowledge of cybersecurity best practices. • Threat-detection experience. • Defensive-security knowledge. • Linux operating-system experience. • Windows operating-system experience. • System-hardening experience. • Security-configuration experience. • Understanding of networking concepts. • Understanding of security protocols. • Understanding of secure-system design. • 5 years of experience supporting large IT environments and/or enterprise system deployments. • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience. Preferred Qualifications • Advanced Cribl Stream experience. • SIEM administration experience. • SIEM analysis experience. • SIEM reporting experience. • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch. • Experience building and deploying Linux-based security sensors. • Enterprise cybersecurity engineering experience. • Security architecture experience. • Security automation experience. • Security-system integration experience. • Knowledge of the NIST Cybersecurity Framework (NIST CSF). • Knowledge of CJIS requirements. • Knowledge of IRS Publication 1075. • Knowledge of CMS MARS-E. • CISSP certification. • Security+ certification. • Location in or near South Carolina with the ability to occasionally report onsite. Additional Requirements • Successful completion of a 7-year standard criminal background check. • Successful completion of a full credit-history check. • Successful completion of a driving-record (MVR) check. • Successful completion of a 10-panel drug screen. • E-Verify employment eligibility verification. • Successful completion of a SLED check. • Ability to obtain and maintain annual CJIS certification. • Availability for occasional onsite needs in South Carolina if requested; onsite travel is the responsibility of the candidate. • Participation in an on-call roster. Work Location and Schedule Location: Remote within the United States (agency located at 4430 Broad River Road, Columbia, South Carolina 29210). Schedule: Day schedule, 40 hours per week, with on-call roster participation. Work Arrangement: 100% remote, with occasional onsite work in South Carolina if requested. All required experience should be clearly and explicitly documented in the resume. Originally posted on Himalayas