Consultant, Cybersecurity (Data Engineer)

NationwideColumbus, OH
$118,000 - $222,000Hybrid

About The Position

Nationwide's Technology team is seeking passionate individuals to enable a Fortune 100 company to drive innovation and adopt new technologies. This role is part of the Cyber Security Operations Center’s Innovation and Integration (CSOC-INI) team, which transforms emerging ideas into secure, production-ready capabilities that advance cyber defense. The team focuses on agentic solutions, modern application engineering, platform foundations, and security data engineering, translating complex operational needs into scalable, observable outcomes. This is a high-impact opportunity to build the security data foundation that powers modern Cyber Security Operations. The role involves designing and operating pipelines, lakehouse data models, and telemetry engineering patterns to convert raw security data into trusted intelligence for detections, analytics, and investigations. Collaboration with cyber security, detection engineering, platform, and data teams is essential to ensure the security data lake is scalable, observable, governed, and supports mission-critical operational decisions.

Requirements

  • Security Operations experience preferred
  • Strong data engineering skills, with advanced Databricks and Spark experience and strong working ability in Python and SQL
  • Experience building and operating batch and streaming data pipelines for high-volume telemetry, logs, events, and security datasets
  • Strong knowledge of telemetry normalization (OCSF), enrichment, schema design, and data quality controls across security-relevant data sources
  • Experience designing and maintaining lakehouse or data lake architectures that support analytics, detections, investigations, and long-term retention needs
  • Familiarity with detection engineering requirements, including how curated data supports rules, analytics, triage, and investigation workflows
  • Experience integrating enterprise data sources, APIs, files, message streams, and cloud storage in a secure and maintainable way
  • Working knowledge of observability, cost management, performance tuning, and operational support for production data platforms
  • Ability to collaborate with architecture, platform, security, governance, and Cyber Security Operations stakeholders
  • Excellent verbal and written communication skills
  • Experience using Windows and Linux/Unix operating systems, administration and tools.
  • Experience with network configurations, protocols, scripting, web application security, network security, firewalls and network topology from both physical and logical viewpoints.
  • Scripting in PowerShell, Python, Bash and Windows Batch.

Nice To Haves

  • Security Operations experience preferred
  • Undergraduate studies in cyber security, management information systems, engineering, math, computer science, data analytics or comparable experience and education strongly preferred.
  • Graduate studies in cyber security, computer science or a related field are a plus.
  • Certified Information Systems Security Professional (CISSP), Cisco Certified Network Associate (CCNA), Certified Ethical Hacker (CEH), GIAC Certified Intrusion Handler (GCIH), Digital Forensics Investigation: EnCase Certified Examiner (EnCE) certification, GIAC Strategic Planning Policy and Leadership (GSTRT), GIAC Security Expert (GSE), Certified Cloud Security Professional (CCSP), AWS Certified Cloud Practitioner, AZ500.
  • Insurance and/or financial services industry knowledge a plus.

Responsibilities

  • Designs, builds, and operates the security data engineering foundation that enables telemetry ingestion, normalization, enrichment, analytics, and detections across the Cyber Security Operations Center.
  • Owns secure and reliable data pipelines, lakehouse data models, telemetry quality controls, and the engineering patterns needed to support security analytics, detection content, investigations, and downstream operational workflows.
  • Partners closely with cyber security professionals, detection engineers, platform and operations engineers, and data consumers to ensure the security data lake is trustworthy, observable, scalable, governed, and production-ready.
  • Build and maintain production-grade data pipelines and lakehouse data products that support telemetry analysis, detections, and cyber security investigations.
  • Define and implement ingestion, parsing, normalization, enrichment, and curation patterns for diverse security and platform telemetry sources.
  • Design trustworthy data models and storage patterns in Databricks that balance performance, cost, lineage, retention, and analytical usability.
  • Partner with detection engineers and analysts to ensure data products expose the fields, context, and quality needed for effective rules and analytics.
  • Implement data quality monitoring, freshness checks, reconciliation controls, and operational telemetry for critical data flows.
  • Optimize jobs, clusters, storage layout, and query performance for scale, reliability, and cost efficiency.
  • Support secure access patterns, governance controls, and auditability requirements for sensitive security data.
  • Troubleshoot pipeline defects, telemetry gaps, and downstream data issues quickly, and support production incident response when data engineering is involved.
  • Continuously improve reusable ingestion frameworks, data standards, and engineering practices across the security data lake ecosystem.
  • Leads or responds to complex cyber incidents using industry recognized methodology, e.g., PICERL (Preparation, Identification, Containment, Eradication, Recovery and Lessons Learned).
  • Creates uplift of cyber security detection and alerts for ongoing prevention of threats.
  • Applies secure software and systems engineering practices throughout the delivery lifecycle to ensure our data and technology solutions are protected from threats and vulnerabilities.
  • Uses an efficiency mindset for incident response to design and implement automation and orchestration for the enrichment and handling of cyber security events.
  • Manages and supports vulnerability management via tools, processes, and proactively identifies vulnerabilities in the environment.
  • Plans and conducts team activities to enrich detection and prevention controls.
  • Plans and delivers proactive cyber activities (purple teaming, threat hunting, red teaming, etc.) with full understanding of the MITRE ATT&CK framework.
  • Identifies critical log sources and system events used for creation and tuning of cyber security detections.
  • Maintains awareness of current cyber threat landscape to perform evaluation, enrichment and dissemination for action to protect Nationwide members and environment.
  • Leads and works on initiatives as part of the overall cyber operations strategy.
  • May perform other responsibilities as assigned.

Benefits

  • medical/dental/vision
  • life insurance
  • short and long term disability coverage
  • paid time off
  • nine paid holidays
  • 8 hours of Lifetime paid time off
  • 8 hours of Unity Day paid time off
  • 401(k) with company match
  • company-paid pension plan
  • business casual attire
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service