Security Data Engineer (Cribl)

Air InfoSec•Columbia, SC
•Remote

About The Position

This is a remote position. The Security Data Engineer will support the South Carolina Department of Administration, Division of Technology Information Security (DIS) on its large-scale enterprise cybersecurity initiatives. The role centers on hands-on Cribl data modeling and log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments. The Data Engineer will work alongside full-time security architects and engineers to strengthen enterprise security-data operations. Responsibilities also include hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, and Linux-based security sensors. The role requires building security automation and integrations using Python and Bash, supporting threat detection, and contributing to defensive security architecture.

Requirements

  • Hands-on Cribl data modeling experience.
  • Cribl log-pipeline design and implementation experience.
  • Strong understanding of enterprise security architecture and engineering principles.
  • Experience implementing and supporting enterprise security tools.
  • Exposure to SIEM technologies.
  • Exposure to XDR technologies.
  • Exposure to vulnerability-management technologies.
  • Exposure to Data Loss Prevention (DLP) technologies.
  • Exposure to endpoint-security technologies.
  • Experience developing automation and integrations using Python and/or Bash.
  • Knowledge of cybersecurity best practices.
  • Threat-detection experience.
  • Defensive-security knowledge.
  • Linux operating-system experience.
  • Windows operating-system experience.
  • System-hardening experience.
  • Security-configuration experience.
  • Understanding of networking concepts.
  • Understanding of security protocols.
  • Understanding of secure-system design.
  • 5 years of experience supporting large IT environments and/or enterprise system deployments.
  • Bachelor's degree in an Information Technology-related or Security-related field, or 8 years of relevant professional experience.
  • Successful completion of a 7-year standard criminal background check.
  • Successful completion of a full credit-history check.
  • Successful completion of a driving-record (MVR) check.
  • Successful completion of a 10-panel drug screen.
  • E-Verify employment eligibility verification.
  • Successful completion of a SLED check.
  • Ability to obtain and maintain annual CJIS certification.
  • Availability for occasional onsite work in South Carolina if requested.
  • Participation in an on-call roster.

Nice To Haves

  • Advanced Cribl Stream experience.
  • SIEM administration experience.
  • SIEM analysis experience.
  • SIEM reporting experience.
  • Experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, or Elastic/Elasticsearch.
  • Experience building and deploying Linux-based security sensors.
  • Enterprise cybersecurity engineering experience.
  • Security architecture experience.
  • Security automation experience.
  • Security-system integration experience.
  • Knowledge of the NIST Cybersecurity Framework (NIST CSF).
  • Knowledge of CJIS requirements.
  • Knowledge of IRS Publication 1075.
  • Knowledge of CMS MARS-E.
  • CISSP certification.
  • Security+ certification.

Responsibilities

  • Design, build, implement, and maintain Cribl data models and log pipelines.
  • Develop enterprise security-data ingestion and routing workflows that deliver security telemetry into enterprise SIEM environments.
  • Perform data parsing, filtering, transformation, enrichment, routing, and normalization of security telemetry.
  • Support SIEM administration, analysis, and reporting.
  • Implement and support enterprise security technologies, including XDR, vulnerability-management, DLP, and endpoint-security platforms.
  • Build and deploy Linux-based security sensors and support Linux and Windows security configuration and hardening.
  • Develop security automation and integrations using Python and Bash.
  • Support threat detection, incident-detection activities, and security-control implementation and validation.
  • Troubleshoot complex security-data and integration issues and support secure networking and system-design initiatives.
  • Collaborate with enterprise security architects and engineers in architecture discussions and participate in the required on-call rotation.

Benefits

  • On-call roster participation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service