Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)

AbbVieNorth Chicago, IL
$84,500 - $162,000Hybrid

About The Position

As a member of the Cyber Security Engineering (CSE) team within Information Security & Risk Management (ISRM), the Data Engineer focuses on expanding data capabilities. This role is responsible for delivering high-value data management solutions, including data pipelines, models, and SIEM platform optimization, to empower analysts and protect the business.

Requirements

  • Bachelor's Degree with 5 years' experience; or Master's Degree with 4 years' experience
  • Experienced in writing and optimizing Splunk’s Search Processing Language (SPL)
  • Proven ability to administer Splunk Enterprise and onboard data sources
  • Skills in developing data models, dictionaries, and reports within a SIEM platform
  • Experience building and configuring data pipelines
  • Experience with regular expressions and parsing unstructured data
  • Deep understanding of data administration and data standardization policies
  • Knowledge of database management systems, query languages, table relationships, and views
  • Experience in validating data sets and calculations
  • Ability to work both independently without direction and within a group for day-to-day activities
  • Capable of learning new concepts and processes quickly, and adapting to a constantly changing environment
  • Experience with CI/CD Pipelines and Git
  • Experience with database & system integration technologies

Nice To Haves

  • Splunk Certified Admin, Power User, or Architect certification
  • Prior experience working in an Agile team
  • Familiarity with cybersecurity, privacy principles, cyber threats, and vulnerabilities
  • Prior experience working with ETL in a SIEM environment (ELK, Splunk, Exabeam, etc.)
  • Experience working with development tools and scripting languages (Python / PowerShell / Go)
  • Experience analyzing and pivoting on large sets of data, with the ability to identify patterns, anomalies, and outliers
  • Cribl Certified User, Admin Stream, or Engineer
  • Demonstrated experience in log analysis and parsing of unstructured data (ETL)
  • Amazon Solutions Architect / Azure Data Engineer Associate / Cloud Professional Data Engineer Certification

Responsibilities

  • Design, implement, and enhance robust streaming and batch data pipelines utilizing message brokers to efficiently feed the SIEM and other downstream analytics engines.
  • Leverage observability pipelines to aggressively route, filter, and normalize/harmonize data, creating structured datasets from unstructured logs prior to SIEM ingestion.
  • Build scalable data models and enhance standard schemas within data warehousing solutions to deliver reliable, cost-effective, query-optimized storage.
  • Verify data integrity and translations across distributed systems and message topics while managing end-to-end data lineage.
  • Analyze requirements to determine the necessary coding, API integrations, and programming activities to connect disparate security telemetry sources into the SIEM, data warehouses, or other repositories.
  • Execute testing plans, debug pipeline routing issues, and thoroughly document data flows, routing configurations, and integration protocols.
  • Perform the compilation, cataloging, caching, and rapid retrieval of telemetry within the SIEM and associated data lakes.
  • Create, manage, and support advanced analytics and reporting environments operating outside the primary SIEM for long-term security analytics and hunting.
  • Define precise data specifications and proactively plan for capacity changes across streaming, routing, indexing, and storage infrastructure.
  • Assist in developing, documenting, and enforcing comprehensive data ingestion standards, parsing policies, and retention procedures across all supported platforms.
  • Analyze diverse data sources across the data stack to uncover trends, improve data quality, and provide actionable recommendations to the security operations team.
  • Develop standards and implement robust automations for metrics aggregation and dissemination, pulling key telemetry from the SIEM and data warehouses.

Benefits

  • paid time off (vacation, holidays, sick)
  • medical/dental/vision insurance
  • 401(k)
  • short-term incentive programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service