SIEM Subject matter expert
Diverse Lynx - Tampa, Florida, us, 33646
Work at Diverse Lynx
Overview
- View job
Overview
Engineer Role Description:
Job Description for SIEM Data Engineer Position Who we are looking for:
The State Street Cyber Data & Analytics team is seeking a SIEM Data Engineer. This team provides models, insights, and tooling to assist Cybersecurity teams in making faster, more informed decisions to secure State Street’s digital footprint. As a SIEM Data Engineer, you will be responsible for designing, implementing, and maintaining solutions that enhance data visibility, transform data, and improve overall data quality. You will collaborate with data product managers, architects, engineers, and other team members to deliver SIEM & analytics functions supporting our mission to build predictive models and intelligent systems for securing State Street’s information and infrastructure. What you will be responsible for:
Onboard cloud-native security logs (AWS, Azure, OCI), infrastructure, and business application security logs to the Splunk/SIEM platform using Cribl Stream and various agents like Splunk UF, Grafana, Opentelemetry, Fluentbit/Fluentd. Collaborate with cross-functional teams to understand data integration requirements and design solutions using CRIBL Stream and Splunk Enterprise. Configure and customize CRIBL Stream to route, filter, and transform data streams from various infrastructure, applications, and public cloud services. Onboard multi-cloud native data sources into SIEM using CRIBL and various integration strategies, highlighting key data trends and flows. Resolve technical issues and help implement strategies to reduce recurrence. Education & Preferred Qualifications
Minimum Qualifications
Primary skills: Splunk data administration, Cribl Stream, GitOps (Cribl code deployed via GitOps), Confluence/Jira. Minimum 6+ years of platform engineering with DevOps experience, with a bachelor’s degree in Computer Science or Engineering. 5+ years of experience in log onboarding to support SIEM and Observability platforms. 2+ years of data pipeline platform implementation experience using tools like Splunk, Cribl, Fluentbit/Fluentd, & Vector.dev. Practical experience with Data Engineering for CIM compliance. Deep understanding of CI/CD tools and a focus on reliable, high-quality releases. Strong GitOps experience. Preferred Experience
Splunk certifications (e.g., Certified Architect or Certified Consultant). CRIBL certifications (e.g., Certified Observability Engineer). Experience in administering Splunk Enterprise Security. Diverse Lynx LLC is an Equal Employment Opportunity employer. All qualified applicants will receive consideration without discrimination. We evaluate solely on ability, competence, and capability. We promote a diverse workforce at all levels.
#J-18808-Ljbffr