Security Observability Engineer: SIEM & Log Pipeline Lead

Starr Insurance Holdings, Inc.

Destin (FL)

On-site

USD 90,000 - 120,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Starr Insurance Holdings, Inc. is seeking a Security Observability Engineer to lead the migration and optimization of our log ingestion and observability pipelines.

You will manage end-to-end SIEM operations, Cribl/ Splunk configurations, and ensure secure, scalable data delivery for high-volume logs. The role requires extensive Splunk SIEM experience, Cribl Stream/Edge proficiency, and strong scripting skills.

Qualifications

  • Extensive hands-on Splunk SIEM engineering experience with indexers, search heads, clustering and CIM.
  • 2+ years with Cribl Stream/Edge, distributed and load-balanced pipelines.
  • Deep understanding of machine data transport (syslog, HEC, TCP/UDP) and high-availability logging.
  • Experience onboarding and tuning security logs (firewalls, cloud, EDR/XDR, IAM).
  • Advanced Splunk SPL, data model, event parsing and alert tuning skills.
  • Scripting/automation in Python or shell for pipeline management.

Responsibilities

  • Lead end-to-end SIEM pipeline management and optimization.
  • Migrate log sources from Splunk ingestion to Cribl Stream/Edge with load-balanced delivery.
  • Architect scalable, resilient pipelines including external load balancers and Cribl worker groups.
  • Onboard and tune log sources for maximum coverage while reducing Splunk ingest costs.
  • Develop and maintain Cribl and Splunk configurations with transformations and masking.
  • Ensure balanced distribution of logging workload across Cribl and Splunk to prevent bottlenecks.
  • Collaborate with SOC/IR to ensure logs reach SIEM efficiently and reliably.
  • Monitor, test, and remediate pipeline health to maximize uptime and visibility.
  • Document security policies, log routing, retention, and integrity; track ingest reductions.
  • Maintain up-to-date documentation of log flows and topology.

Skills

Splunk SIEM engineering
Cribl Stream/Edge
Log ingestion & routing
SPL & data modeling
Scripting (Python)
Monitoring dashboards
SOC/IR collaboration

Tools

Cribl Stream/Edge
Splunk SIEM
Load balancing / HA

Job description

Starr Insurance Holdings, Inc. is seeking a Security Observability Engineer to lead the migration and optimization of our log ingestion and observability pipelines.

You will manage end-to-end SIEM operations, Cribl/ Splunk configurations, and ensure secure, scalable data delivery for high-volume logs. The role requires extensive Splunk SIEM experience, Cribl Stream/Edge proficiency, and strong scripting skills.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Observability Engineer: SIEM & Splunk Lead
Security Observability Engineer: SIEM & Splunk Lead

Starr Companies • New York (NY)

On-site
USD 90,000 - 120,000
First class training and development opportunities
Inclusive environment and equal opportunity employer
Senior Security Observability Engineer - SIEM & Splunk
Senior Security Observability Engineer - SIEM & Splunk

Starr • Destin (FL)

On-site
USD 100,000 - 130,000
Security Observability Engineer
Security Observability Engineer

Starr • Destin (FL)

On-site
USD 100,000 - 130,000
Security Observability Engineer
Security Observability Engineer

Starr Insurance Holdings, Inc. • Destin (FL)

On-site
USD 90,000 - 120,000
Security Observability Engineer
Security Observability Engineer

Starr Companies • New York (NY)

On-site
USD 90,000 - 120,000
First class training and development opportunities
Inclusive environment and equal opportunity employer
Senior Cribl Engineer – Data Pipelines & SIEM
Senior Cribl Engineer – Data Pipelines & SIEM

Disruptive Solutions, LLC • Washington, Northern (KY)

Hybrid
USD 110,000 - 170,000
Senior SIEM Data Engineer Lead Security Telemetry Pipelines
Senior SIEM Data Engineer Lead Security Telemetry Pipelines

Shain Associates • Quincy (MA)

Hybrid
USD 140,000 - 190,000
Splunk Platform Engineer - SIEM & Data Pipeline Ownership
Splunk Platform Engineer - SIEM & Data Pipeline Ownership

Experis Technology Group • Richmond (VA)

On-site
USD 90,000 - 96,000
Health benefits
Dental plan
Vision plan
+2
Sr SIEM Data Engineer
Sr SIEM Data Engineer

Shain Associates • Quincy (MA)

Hybrid
USD 140,000 - 190,000
Observability Pipeline Engineer
Observability Pipeline Engineer

Booz Allen Hamilton • McLean (VA)

On-site
USD 120,000 - 180,000