Engineer III – SIEM Integrations

Jobtailor

New York (NY)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Senior Data Integration Engineer to design, develop, and maintain data connectors for SIEM platforms, focusing on secure data ingestion and normalization. You will collaborate across teams to validate connectors in lab environments, troubleshoot ingestion issues, and produce robust documentation for integration methods and troubleshooting guides.

Ideal candidates have 6+ years in cybersecurity, experience with major SIEMs, and strong programming skills in Python or Go,

Qualifications

  • Bachelor’s or Master’s degree in CS or related field (or equivalent work experience).
  • 6+ years of experience in cybersecurity and SIEM integrations.
  • Experience in developing data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, QRadar etc.
  • Experience in security data normalization schemas, parsing and data enrichment.
  • Experience in setting up and managing environments for security products such as Firewalls, IDS/IPS, EDR, CASB, Identity Security, Email Security etc.
  • Experience with security events and its formats such as Syslog, CEF, LEEF, JSON, XML.
  • Working knowledge of log processing or shipping tools such as Cribl, Splunk forwarder, Azure monitoring agent, LogScale log collector etc.
  • Working knowledge on cloud-native logging services such as AWS CloudWatch, Azure Monitor, or GCP Logging
  • Proficiency in at least one programming language, preferably Python or Go
  • Strong documentation, communication and customer interaction skills
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and drive business outcomes.

Responsibilities

  • Evaluate, develop, maintain, and enhance data connectors and parsers to ingest data from third-party security products into CrowdStrike Next-Gen SIEM
  • Set up and maintain a lab or test environment for security products to validate data connectors and troubleshoot issues
  • Troubleshoot and resolve issues with existing data connectors to ensure reliable log ingestion
  • Collaborate with internal teams to define efficient logging, error handling, data normalization and documentation for data connectors
  • Research and implement best practices for ingesting security logs from Firewalls, IDS/IPS, Cloud Security products, Endpoint Security, and other security products and platforms
  • Write and maintain high-quality technical documentation for integration methods and troubleshooting guides
  • Provide on-call support for critical data ingestion issues and production incidents
  • Work with customers, customer success and customer support teams to troubleshoot and resolve data ingestion-related issues and ensure effective communication

Skills

Data Connector Development
Security Data Normalization
Python Programming
Go Programming
Log Processing
Data Ingestion Pipelines
Troubleshooting
Technical Documentation
AI Technologies Utilization
Cybersecurity
Cloud-Native Logging

Education

Bachelors or Masters in Computer Science

Tools

CrowdStrike Next-Gen SIEM
Splunk
Sentinel
Exabeam
QRadar
Cribl
Azure Monitoring Agent
AWS CloudWatch
GCP Logging
LogScale Log Collector

Job description

  • Evaluate, develop, maintain, and enhance data connectors and parsers to ingest data from third-party security products into CrowdStrike Next-Gen SIEM
  • Set up and maintain a lab or test environment for security products to validate data connectors and troubleshoot issues
  • Troubleshoot and resolve issues with existing data connectors to ensure reliable log ingestion
  • Collaborate with internal teams to define efficient logging, error handling, data normalization and documentation for data connectors
  • Research and implement best practices for ingesting security logs from Firewalls, IDS/IPS, Cloud Security products, Endpoint Security, and other security products and platforms
  • Write and maintain high-quality technical documentation for integration methods and troubleshooting guides
  • Provide on-call support for critical data ingestion issues and production incidents
  • Work with customers, customer success and customer support teams to troubleshoot and resolve data ingestion-related issues and ensure effective communication
Requirements
  • Bachelor’s or Master’s degree in Computer Science or related field or equivalent work experience.
  • 6+ years of experience in cybersecurity and SIEM integrations
  • Experience in developing data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, QRadar etc.
  • Experience in security data normalization schemas, parsing and data enrichment
  • Experience in setting up and managing environments for security products such as Firewalls, IDS/IPS, EDR, CASB, Identity Security, Email Security etc.
  • Experience with security events and its formats such as Syslog, CEF, LEEF, JSON, XML
  • Working knowledge of log processing or shipping tools such as Cribl, Splunk forwarder, Azure monitoring agent, LogScale log collector etc.
  • Working knowledge on cloud-native logging services such as AWS CloudWatch, Azure Monitor, or GCP Logging
  • Proficiency in at least one programming language, preferably Python or Go
  • Strong documentation, communication and customer interaction skills
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.
Core Competencies

Demonstrates expertise in developing and maintaining data connectors for SIEM platforms, with a strong focus on security data normalization and troubleshooting. Proficient in utilizing programming languages and cloud-native logging services to enhance data ingestion processes and ensure effective communication with stakeholders.

Highest-signal resume keywords
  • SIEM Integration Experience
  • Data Connector Development
  • Security Data Normalization
  • Python Programming
  • Cloud-Native Logging Services
ATS Optimization Keywords
Hard Skills
  • Data Connector Development
  • Security Data Normalization
  • Python Programming
  • Go Programming
  • Log Processing
  • Data Ingestion Pipelines
  • Troubleshooting
  • Technical Documentation
  • AI Technologies Utilization
  • Cybersecurity
Soft Skills
  • Communication Skills
  • Customer Interaction Skills
  • Collaboration
Industry Keywords
  • Cybersecurity
  • Data Ingestion
  • Security Products
  • Firewalls
  • IDS/IPS
  • EDR
  • CASB
  • Identity Security
  • Email Security
  • Syslog
Tools & Technologies
  • CrowdStrike Next-Gen SIEM
  • Splunk
  • Sentinel
  • Exabeam
  • QRadar
  • Cribl
  • Azure Monitoring Agent
  • AWS CloudWatch
  • GCP Logging
  • LogScale Log Collector
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Automation, Cybersecurity Engineer
Senior Automation, Cybersecurity Engineer

Jobtailor • Plano (TX)

On-site
USD 140,000 - 190,000
Engineer III – SIEM Integrations (Hybrid)
Engineer III – SIEM Integrations (Hybrid)

CrowdStrike • New York (NY)

Hybrid
USD 120,000 - 180,000
Market leader compensation & equity
Wellness programs
Generous vacation & holidays
+5
IT Security SIEM Engineer – Splunk Experience Required
IT Security SIEM Engineer – Splunk Experience Required

Jobtailor • New York (NY)

On-site
USD 120,000 - 160,000
Senior Identity Protection Specialist
Senior Identity Protection Specialist

Jobtailor • Morrisville (NC)

On-site
USD 140,000 - 190,000
Network Security Engineer
Network Security Engineer

Jobtailor • New Jersey

On-site
USD 110,000 - 140,000
Engineer II – Cyber Incident Response
Engineer II – Cyber Incident Response

Jobtailor • Pennsylvania

On-site
USD 70,000 - 100,000
SIEM Engineer II
SIEM Engineer II

SCIGON • Austin (TX)

On-site
USD 149,000 - 166,000
Senior Engineer – Product Insights
Senior Engineer – Product Insights

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Senior Cybersecurity Ops Analyst
Senior Cybersecurity Ops Analyst

Jobtailor • Santa Ana (CA)

On-site
USD 75,000 - 120,000
Associate Director, Threat Management Center
Associate Director, Threat Management Center

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000