Data Platform Engineer, Cybersecurity Operations

Citi•Irving, TX
•$156,160 - $234,240•Onsite

About The Position

We are seeking a Data Platform Engineer with deep, specialized expertise in data platform architecture and engineering to build and operate the scalable data pipelines, storage backbones, and data lakes that power our next-generation cybersecurity operations capabilities. This role sits at the foundation of our security analytics capability, ingesting and normalizing massive volumes of SOC telemetry into modern, high-performance analytics platforms. This is a deep technical architecture and platform engineering role. We are looking for someone who has genuinely mastered the craft of designing, scaling, and operating enterprise-grade data platforms — not a generalist engineer, but a specialist capable of making foundational architectural decisions that will shape how security data is stored, queried, and consumed for years to come.

Requirements

  • Deep, demonstrable expertise in data platform architecture and engineering - a proven track record of architecting and operating large-scale, mission-critical data platforms from the ground up, with strong judgment on trade-offs across scalability, cost, performance, and reliability.
  • Extensive, hands-on experience building and operating large-scale data pipelines (batch and streaming) using technologies such as Cribl, Kafka, Spark, Flink, Airflow, or equivalent.
  • Deep expertise in data lake and data warehouse architecture (e.g., Delta Lake, Iceberg, Snowflake, BigQuery, Redshift) at enterprise scale, including experience making foundational design decisions on storage formats, partitioning strategies, and query engines.
  • Proven, in-depth experience with cloud-native data infrastructure (AWS/Azure/GCP), including storage tiering, cost optimization, and event-driven architectures.
  • Strong understanding of security telemetry types — logs, network flow, endpoint/EDR data, identity events, cloud audit logs — and the architectural challenges of ingesting and normalizing them at scale.
  • Advanced proficiency in a major programming language (Python, Go, Java, or Scala) for pipeline development and automation.
  • Deep experience with schema design, data modeling, and metadata management for large, heterogeneous, high-velocity datasets.
  • Solid grounding in cybersecurity fundamentals, particularly SOC/OSVM operations, log management, and detection/analytics use cases.
  • Extensive experience with database technologies spanning relational, NoSQL, time-series, and columnar/analytical stores.
  • Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, automated testing, and observability/monitoring practices.
  • Demonstrated ability to architect for scale and reliability in mission-critical, 24x7 operational environments.
  • Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and data science teams.

Nice To Haves

  • 10+ years of experience in architecting data platforms specifically for SOC, SIEM, or XDR environments.
  • Familiarity with AI/ML pipeline requirements (feature stores, training data pipelines) to support advanced security analytics.
  • Deep experience with open table formats (Iceberg, Delta Lake, Hudi) and modern lakehouse architectures.
  • Relevant certifications (e.g., cloud data engineering certifications, GIAC) are a plus but not required in lieu of hands-on expertise.

Responsibilities

  • Design, build, and operate scalable, resilient, high-throughput data pipelines (batch and streaming) that ingest security relevant telemetry - logs, alerts, network flow data, endpoint events, identity signals, and cloud events - from across the enterprise.
  • Develop robust normalization and enrichment logic to transform heterogeneous SOC telemetry formats into standardized schemas consumable by downstream analytics and detection platforms.
  • Architect and maintain the storage backbone (data lakes, warehouses, streaming stores) that serves as the durable, queryable source of truth for SOC data at enterprise scale.
  • Build and operate data lake infrastructure optimized for high-volume security telemetry, balancing cost, performance, retention, and query flexibility.
  • Ensure seamless, low-latency delivery of normalized SOC data into modern analytics platforms, SIEM/XDR tooling, and other downstream systems.
  • Continuously tune pipeline throughput, storage partitioning, and query performance to keep pace with growing telemetry volume and evolving analytics demands.
  • Implement monitoring, alerting, and self-healing capabilities to ensure pipeline uptime, data completeness, and data quality at production scale.
  • Define and enforce data schemas, taxonomies, and metadata standards across ingested telemetry sources to enable consistent downstream consumption.
  • Build reusable frameworks and automation to rapidly onboard new telemetry sources as the tool and sensor ecosystem expands.
  • Ensure secure handling, encryption, access control, and regulatory compliance for sensitive security data throughout its lifecycle (ingestion, storage, processing, access).
  • Partner closely with cybersecurity operations analysts, detection engineers, threat and exposure management teams, and data science teams to ensure the platform meets operational and analytical needs.
  • Maintain clear architecture documentation, data dictionaries, and operational runbooks to support platform sustainability and team scalability.

Benefits

  • medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service