Lead SIEM Engineer – Cyber Command Center (C3)
The Lead SIEM Engineer serves as a senior technical authority supporting a variety of global enterprise information security services for the Chief Information Security Officer. The role focuses on the architecture, engineering, and optimization of three core platforms: Splunk Cloud, Amazon Web Services (AWS), and Cribl.
About the Role
The Lead SIEM Engineer is the senior technical lead for building, maintaining, and evolving the infrastructure that collects, correlates, and identifies indicators of malicious or inappropriate activity. This individual must manage security‑relevant data to facilitate intrusion detection, log analysis, and incident response at enterprise scale. The role is a primary escalation path for complex events, provides architectural guidance, and shapes the long‑term direction of the SIEM and data ingestion program.
Responsibilities
- Splunk Cloud
- Design, configure, grow, and maintain the Splunk Cloud platform ensuring high availability, performance, and scalability.
- Develop advanced content (correlation searches, dashboards, reports, and data models) aligned to CIM compliance.
- Manage and optimize Splunk configuration (Props, Transforms, Field Extractions, Heavy Forwarders, HEC endpoints).
- Onboard new data sources, ensuring proper parsing, normalization, and CIM compliance.
- Improve Splunk Enterprise Security use‑case development and tuning.
- AWS
- Design, implement, and manage AWS infrastructure supporting SIEM data pipelines and security operations.
- Utilize AWS services (S3, Kinesis, Lambda, CloudWatch, IAM, etc.) to support scalable, secure data flows into the SIEM environment.
- Ensure cloud‑native log sources are properly integrated and optimized within the security data ecosystem.
- Collaborate with Cloud and Infrastructure teams to maintain AWS security posture aligned with organizational standards.
- Identify and implement AWS cost optimization strategies related to security data storage and processing.
- Cribl (Data Ingestion)
- Lead Cribl architecture, deployment, and ongoing administration.
- Design and manage Cribl pipelines to route, filter, transform, and enrich security‑relevant data before ingestion into Splunk Cloud or other destinations.
- Optimize data flows to reduce noise, improve data quality, and manage licensing costs across the SIEM platform.
- Evaluate and onboard new data sources through Cribl, ensuring consistent standards for data formatting and delivery.
- Maintain Cribl routing logic in alignment with data retention and security policies.
- Additional Responsibilities
- Support SIEM program KPI development and reporting with Security Leadership.
- Define, build, and govern an Information Security Data Retention lifecycle across cloud and on‑premise environments.
- Support and drive vendor relationship strategy for SIEM and data ingestion tooling.
- Analyze and respond to security‑relevant alerts and events; serve as a senior escalation point for Analysts and junior SIEM Engineers.
- Mentor junior and mid‑level team members, fostering knowledge sharing and technical growth.
- Collect, assess, and report threat intelligence and actionable security information, adjusting tactical operations accordingly.
- Identify business risk and advise appropriate contacts to address and treat such risk.
- Support automation and continuous improvement of overall Information Security posture.
- Assist with remediation plans for gaps identified in audits or recommended process improvements.
- Proactively seek new technical solutions and identify capability gaps, prioritizing risk‑based decisions.
- Maintain job knowledge by tracking and understanding emerging security practices and standards; engage in professional development.
- Perform other related duties as assigned in support of broader Security & Risk program efforts.
Requirements
- Education: BA or BS in Computer Science, Management Information Systems, Engineering, or related field (desirable); MS in a related field is desired. Practical experience, education, and certifications may also be considered.
- Experience: 7+ years of progressive experience in computing with a strong emphasis on SIEM engineering, architecture, and administration.
- Splunk: 5+ years of hands‑on experience with Splunk Cloud, architecture, administration, content development, and CIM compliance (HEC, Props, Transforms, Extractions, Dashboarding, Splunk ES, etc.).
- AWS: 5+ years of demonstrated experience working within AWS, including security‑relevant services such as S3, Kinesis, Lambda, CloudWatch, IAM, and related data pipeline tooling.
- Cribl: 3+ years of hands‑on experience with Cribl or comparable data pipeline/log routing technologies (e.g., Kafka, Logstash) in an enterprise environment.
- Other SIEM platforms: Experience with ArcSight, QRadar, ELK, LogLogic, etc. is considered a plus.
- Networking: Documented understanding of core network protocols (TCP/IP, ICMP, DHCP, DNS, etc.).
- Programming: Familiarity with Python, PowerShell, Java, C#, Bash, etc.
- Linux: Vast knowledge within Linux environments, including editing and maintaining configuration files and applications.
- Certifications (Desired): Splunk Certified Administrator, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, AWS Certified Security – Specialty or AWS Certified Solutions Architect, Cribl Certifications (where applicable).
- Skills & Competencies: Strong leadership presence, excellent communication (oral, written, presentation), consultative abilities, ability to mentor and influence technical direction, data‑driven decision making under ambiguous circumstances.
Additional Information
This position requires some weekend and evening assignments as well as availability during off‑hours for scheduled and unscheduled activities.
EEO Statement
Asurion is an equal opportunity employer. We hire the best available person for the job regardless of marital status, sex, gender orientation, age, religious belief, race, nationality and ethnic origin, color, or disability.