Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)

PowerToFly

North Chicago (IL)

On-site

USD 100,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k)
Paid time off

Job summary

AbbVie is seeking a Data Engineer within the Cyber Security Engineering team to expand data capabilities, build scalable pipelines, and optimize SIEM data ingestion. You will transform unstructured logs into structured datasets, model data for warehousing, and ensure end-to-end data lineage while integrating diverse telemetry sources.

The role requires strong SPL, Splunk Enterprise administration, and CI/CD experience, with a focus on governance, data standardization, and analytics tooling

Qualifications

  • Bachelor's degree with 5+ years' experience or Master's degree with 4+ years' experience.
  • Experience writing and optimizing Splunk Search Processing Language (SPL).
  • Proven ability to administer Splunk Enterprise and onboard data sources.
  • Skills in developing data models, dictionaries, and reports within a SIEM platform.
  • Experience building and configuring data pipelines.
  • Experience with regular expressions and parsing unstructured data.
  • Deep understanding of data administration and data standardization policies.
  • Knowledge of database management systems, query languages, tables, and views.
  • Experience validating data sets and calculations.
  • Ability to work independently and in a team.
  • Capable of learning new concepts quickly.
  • Experience with CI/CD Pipelines and Git.
  • Experience with database & system integration technologies.

Responsibilities

  • Data Pipeline Development: Design, implement, and enhance streaming and batch data pipelines feeding SIEM and analytics engines.
  • Data Transformation & Normalization: Route, filter, and harmonize data into structured datasets from logs.
  • Data Modeling & Architecture: Build scalable data models and optimize storage in data warehouses.
  • Data Integrity & Lineage: Verify data integrity across distributed systems and manage end-to-end lineage.
  • Development & Integration: Connect security telemetry sources to SIEM, data warehouses, or repositories.
  • Testing & Quality Assurance: Execute tests, debug routing issues, and document data flows.
  • Data Management Operations: Catalogue, cache, and retrieve telemetry in SIEM and data lakes.
  • Analytics Toolsets: Support analytics environments outside SIEM for long-term security analytics.
  • Requirements & Capacity Planning: Define data specs and plan capacity changes.
  • Governance & Standards: Enforce data ingestion standards and retention policies.
  • Actionable Insights: Analyze data to uncover trends and improve data quality.
  • Metrics Automation: Implement automation for metrics aggregation from SIEM and warehouses.

Skills

Splunk SPL
Splunk Enterprise
Data pipelines
CI/CD Pipelines
Python
Regex
ETL
Cribl
PowerShell
Go

Education

Bachelor's Degree + 5 years experience
Master's Degree + 4 years experience

Tools

Splunk
ELK
Exabeam
Cribl
Git
Python
PowerShell
Go

Job description


Company Description

About AbbVie

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us atwww.abbvie.com. Follow @abbvie onLinkedIn,Facebook,Instagram,XandYouTube.


Job Description

As a member of the Cyber Security Engineering (CSE) team within Information Security & Risk Management (ISRM), the Data Engineer focuses on expanding data capabilities. This roleis responsible fordelivering high-value data management solutions, including data pipelines, models, and SIEM platform optimization, to empower analysts and protect the business.

Responsibilities:

  • Data Pipeline Development:Design, implement, and enhance robust streaming and batch data pipelinesutilizingmessage brokers to efficiently feed the SIEM and other downstream analytics engines.
  • Data Transformation & Normalization:Leverage observability pipelines to aggressively route, filter, and normalize/harmonize data, creating structured datasets from unstructured logs prior to SIEM ingestion.
  • Data Modeling & Architecture:Build scalable data models and enhance standard schemas within data warehousing solutions to deliver reliable, cost-effective, query-optimized storage.
  • Data Integrity & Lineage:Verify data integrity and translations across distributed systems and message topics while managing end-to-end data lineage.
  • Development & Integration:Analyze requirements todeterminethe necessary coding, API integrations, and programming activities to connect disparate security telemetry sources into the SIEM, data warehouses, or other repositories.
  • Testing & Quality Assurance:Execute testing plans, debug pipeline routing issues, and thoroughly document data flows, routing configurations, and integration protocols.
  • Data Management Operations:Perform the compilation, cataloging, caching, and rapid retrieval of telemetry within the SIEM and associated data lakes.
  • Analytics Toolsets:Create, manage, and support advanced analytics and reporting environmentsoperatingoutside the primary SIEM for long-term security analytics and hunting.
  • Requirements & Capacity Planning:Define precise data specifications and proactively plan for capacity changes across streaming, routing, indexing, and storage infrastructure.
  • Governance & Standards:Assist in developing, documenting, and enforcing comprehensive data ingestion standards, parsing policies, and retention procedures across all supported platforms.
  • Actionable Insights: Analyze diverse data sources across the data stack to uncover trends, improve data quality, and provide actionable recommendations to the security operations team.
  • Metrics Automation:Develop standards and implement robust automations for metrics aggregation and dissemination, pulling key telemetry from the SIEM and data warehouses.

Qualifications

Required:

  • Bachelor's Degree with 5years'experience; or Master's Degree with 4years' experience
  • Experienced in writing andoptimizingSplunk’s Search Processing Language (SPL)
  • Proven ability to administer Splunk Enterprise and onboard data sources
  • Skills in developing data models, dictionaries, and reports within a SIEM platform
  • Experience building and configuring data pipelines
  • Experience with regular expressions and parsing unstructured data
  • Deep understanding of data administration and data standardization policies
  • Knowledge of database management systems, query languages, table relationships, and views
  • Experience in validating data sets and calculations
  • Ability to work both independently without direction and within a group for day-to-day activities
  • Capable of learning new concepts and processes quickly, and adapting to a constantly changing environment
  • Experience with CI/CD Pipelines and Git
  • Experience with database & system integration technologies

Preferred:

  • Splunk Certified Admin, Power User, or Architect certification
  • Prior experience working in an Agile team
  • Familiarity with cybersecurity, privacy principles, cyber threats, and vulnerabilities
  • Prior experience working with ETL in a SIEM environment (ELK, Splunk,Exabeam,etc.)
  • Experience working with development tools and scripting languages (Python / PowerShell / Go)
  • Experience analyzing and pivoting on large sets of data, with the ability toidentifypatterns, anomalies, and outliers
  • Cribl Certified User, Admin Stream, or Engineer
  • Demonstrated experience in log analysis and parsing of unstructured data (ETL)
  • Amazon Solutions Architect / Azure Data Engineer Associate / Cloud Professional Data Engineer Certification

Additional Information

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state orlocal law:

  • The compensation range described below is the range of possible base pay compensation that the Companybelieves ingood faith it will pay for this role at thetimeofthis posting based on the job grade for this position.Individualcompensation paid within this range will depend on many factors including geographiclocation,andwemay ultimately pay more or less than the posted range. This range may bemodified in thefuture.

  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick),medical/dental/visioninsurance and 401(k) to eligibleemployees.

  • This job is eligible toparticipate in our short-term incentiveprograms.

Note: No amount of payis considered to bewages or compensation until such amount is earned, vested, anddeterminable.Theamountandavailabilityof anybonus,commission, incentive, benefits, or any other form ofcompensation and benefitsthat are allocable to a particular employeeremains in the Company'ssoleandabsolutediscretion unless and until paid andmay bemodified at the Company’s sole and absolute discretion, consistent withapplicable law.

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.

US & Puerto Rico only - to learn more, visithttps://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Site Reliability Engineer (Hybrid)
Site Reliability Engineer (Hybrid)

BioSpace • North Chicago (IL)

Hybrid
USD 120,000 - 170,000
Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)
Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)

BioSpace • North Chicago (IL)

On-site
USD 100,000 - 140,000
Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)
Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)

AbbVie • North Chicago (IL)

On-site
USD 115,000 - 170,000
Senior Engineer, Technology II (Data Engineering & Architecture)
Senior Engineer, Technology II (Data Engineering & Architecture)

BioSpace • North Chicago (IL)

On-site
USD 140,000 - 190,000
Site Reliability Engineer (Hybrid)
Site Reliability Engineer (Hybrid)

Allergan • North Chicago (IL)

Hybrid
USD 120,000 - 160,000
Software Engineer - Information Security (Hybrid)
Software Engineer - Information Security (Hybrid)

BioSpace • North Chicago (IL)

On-site
USD 140,000 - 190,000
Senior Cybersecurity Software Engineer (Remote)
Senior Cybersecurity Software Engineer (Remote)

Initial Therapeutics, Inc. • Austin (TX)

Remote
USD 106,000 - 203,000
Comprehensive benefits package
Paid time off
401(k) options
+1
Junior Application Security Engineer
Junior Application Security Engineer

BioSpace • North Chicago (IL)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

BioSpace • North Chicago (IL)

On-site
USD 140,000 - 180,000
Health insurance
401(k) plan
Paid time off
+1
Associate Director - Security Strategy & Analytics (Hybrid)
Associate Director - Security Strategy & Analytics (Hybrid)

AbbVie • Mettawa (IL)

On-site
USD 180,000 - 250,000
Comprehensive benefits
Long-term incentive programs