Unknown Company

Engineer III – SIEM Integrations

new york, ny • Posted 1 weeks ago
Onsite Full Time IT & Technology

  • Evaluate, develop, maintain, and enhance data connectors and parsers to ingest data from third-party security products into CrowdStrike Next-Gen SIEM
  • Set up and maintain a lab or test environment for security products to validate data connectors and troubleshoot issues
  • Troubleshoot and resolve issues with existing data connectors to ensure reliable log ingestion
  • Collaborate with internal teams to define efficient logging, error handling, data normalization and documentation for data connectors
  • Research and implement best practices for ingesting security logs from Firewalls, IDS/IPS, Cloud Security products, Endpoint Security, and other security products and platforms
  • Write and maintain high-quality technical documentation for integration methods and troubleshooting guides
  • Provide on-call support for critical data ingestion issues and production incidents
  • Work with customers, customer success and customer support teams to troubleshoot and resolve data ingestion-related issues and ensure effective communication

Requirements

  • Bachelor’s or Master’s degree in Computer Science or related field or equivalent work experience.
  • 6+ years of experience in cybersecurity and SIEM integrations
  • Experience in developing data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, QRadar etc.
  • Experience in security data normalization schemas, parsing and data enrichment
  • Experience in setting up and managing environments for security products such as Firewalls, IDS/IPS, EDR, CASB, Identity Security, Email Security etc.
  • Experience with security events and its formats such as Syslog, CEF, LEEF, JSON, XML
  • Working knowledge of log processing or shipping tools such as Cribl, Splunk forwarder, Azure monitoring agent, LogScale log collector etc.
  • Working knowledge on cloud-native logging services such as AWS CloudWatch, Azure Monitor, or GCP Logging
  • Proficiency in at least one programming language, preferably Python or Go
  • Strong documentation, communication and customer interaction skills
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Core Competencies

Demonstrates expertise in developing and maintaining data connectors for SIEM platforms, with a strong focus on security data normalization and troubleshooting. Proficient in utilizing programming languages and cloud-native logging services to enhance data ingestion processes and ensure effective communication with stakeholders.

Highest-signal resume keywords

  • SIEM Integration Experience
  • Data Connector Development
  • Security Data Normalization
  • Python Programming
  • Cloud-Native Logging Services

ATS Optimization Keywords

Hard Skills

  • Data Connector Development
  • Security Data Normalization
  • Python Programming
  • Go Programming
  • Log Processing
  • Data Ingestion Pipelines
  • Troubleshooting
  • Technical Documentation
  • AI Technologies Utilization
  • Cybersecurity

Soft Skills

  • Communication Skills
  • Customer Interaction Skills
  • Collaboration

Industry Keywords

  • Cybersecurity
  • Data Ingestion
  • Security Products
  • Firewalls
  • IDS/IPS
  • EDR
  • CASB
  • Identity Security
  • Email Security
  • Syslog

Tools & Technologies

  • CrowdStrike Next-Gen SIEM
  • Splunk
  • Sentinel
  • Exabeam
  • QRadar
  • Cribl
  • Azure Monitoring Agent
  • AWS CloudWatch
  • GCP Logging
  • LogScale Log Collector

#J-18808-Ljbffr
Back to Job Search