Senior CyberTech Engineer (Specialist - Data Sciences)
About this role
Title: CyberTech Engineer
Location: Irving, Tx (Hybrid)
This role requires a senior BFT CyberTech Engineer with deep handson expertise in modern cloudnative security platform engineering spanning SIEM data pipeline data lake and SOAR technologies The consultant will be a critical technical contributor in delivering a Unified AIDriven SOC capability a federated broadcapability query and orchestration system that unifies SOC operations threat intelligence log management incident case management and broader security data underpinned by a configurable AI agent layer for incident and event investigation
Key Responsibilities
· Cloud Native SIEM Engineering
· Architect deploy and operate modern cloudnative SIEM platforms eg Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent at enterprise scale
· Design and implement federated query capabilities enabling broad crossdomain search across SOC intelligence log management and case management data sources
· Develop and maintain detection content correlation rules and dashboards aligned to SOC operational requirements and threat use cases
· Optimize SIEM performance data tiering and retention strategies to balance cost coverage and query fidelity
· Data Pipeline Engineering Cribl
· Design build and manage enterprisegrade data pipelines using Cribl Stream andor Cribl Edge for log routing enrichment transformation filtering and normalization at scale
· Implement Criblbased data management strategies to optimize data volume reduce ingest costs and ensure highfidelity event delivery to SIEM and data lake destinations
· Develop Cribl pipelines that support multidestination routing across SIEM data lake and cold storage tiers
· Collaborate with detection engineering and threat intelligence teams to enrich pipeline data with contextual security signals
· Security Data Lake Engineering
· Architect and manage a scalable cloudnative security data lake eg on AWS S3Athena GCP BigQuery or Snowflake for longterm log retention threat hunting and AIML workloads
· Develop data models schemas and partitioning strategies optimized for security analytics and federated query performance
· Enable broadcapability query access across SOC intel and incident data stored within the data lake supporting both realtime and retrospective investigation workflows
· Integrate data lake telemetry with SIEM and SOAR platforms to support unified investigation and orchestration
· SOAR Platform Engineering
· Design deploy and maintain SOAR platform infrastructure eg Palo Alto XSOAR Splunk SOAR Google SecOps SOAR or equivalent to enable automated incident response and orchestration workflows
· Build and maintain SOAR playbooks and integrations that span SOC case management threat intelligence SIEM ing and external security tooling
· Engineer orchestration workflows that leverage AI agent capabilities for automated event triage enrichment and investigation recommendations
· Continuously improve SOAR operational efficiency through playbook tuning integration maintenance and metricdriven optimization
· AIDriven SOC Enablement
· Contribute to the design and implementation of a configurable AI agent layer for incident and event investigation integrating with SIEM SOAR data lake and case management systems
· Engineer the data and API connectivity required to support AI agent queries context retrieval and automated investigation workflows across federated SOC data sources
· Collaborate with data science AIML engineering and detection engineering teams to operationalize AIdriven investigation and triage capabilities within the SOC platform
· Support the evaluation and integration of emerging AIGenAI security operations tooling aligned to the unified SOC vision
· Platform Integration Federated Architecture
· Design and implement integration patterns that connect SIEM data pipeline data lake SOAR and case management platforms into a cohesive federated SOC data fabric
· Develop and maintain APIs webhooks and data connectors to ensure seamless interoperability across the SOC technology ecosystem
· Apply cloudnative engineering best practices IaC CICD containerization to SOC platform deployment configuration management and operational scaling
Required Skills Experience
· Experience 7 years in cybersecurity or security platform engineering with demonstrable handson experience across SIEM data pipeline data lake and SOAR technologies in enterprise environments
· SIEM
· Deep expertise in one or more modern cloudnative SIEM platforms Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent
· Experience with federated search data normalization eg UDM OCSF and largescale detection content management
· Data Pipeline Cribl Required
· Strong handson proficiency with Cribl Stream andor Cribl Edge for enterprise log management routing enrichment and transformation
· Experience designing multidestination Cribl pipelines across SIEM data la
Frequently Asked Questions
What is the salary for the Senior CyberTech Engineer (Specialist - Data Sciences) role at LTM?
Where is the Senior CyberTech Engineer (Specialist - Data Sciences) position at LTM located?
Is the Senior CyberTech Engineer (Specialist - Data Sciences) role at LTM full-time or part-time?
How do I apply for the Senior CyberTech Engineer (Specialist - Data Sciences) position at LTM?
When was the Senior CyberTech Engineer (Specialist - Data Sciences) job at LTM posted?
You'll be redirected to LTM's official application page on ripplehire.