Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)
Responsibilities
- Data Pipeline Development: Design, implement, and enhance robust streaming and batch data pipelines utilizing message brokers to efficiently feed the SIEM and other downstream analytics engines.
- Data Transformation & Normalization: Leverage observability pipelines to aggressively route, filter, and normalize/harmonize data, creating structured datasets from unstructured logs prior to SIEM ingestion.
- Data Modeling & Architecture: Build scalable data models and enhance standard schemas within data warehousing solutions to deliver reliable, cost-effective, query-optimized storage.
- Data Integrity & Lineage: Verify data integrity and translations across distributed systems and message topics while managing end-to-end data lineage.
- Development & Integration: Analyze requirements to determine the necessary coding, API integrations, and programming activities to connect disparate security telemetry sources into the SIEM, data warehouses, or other repositories.
- Testing & Quality Assurance: Execute testing plans, debug pipeline routing issues, and thoroughly document data flows, routing configurations, and integration protocols.
- Data Management Operations: Perform the compilation, cataloging, caching, and rapid retrieval of telemetry within the SIEM and associated data lakes.
- Analytics Toolsets: Create, manage, and support advanced analytics and reporting environments operating outside the primary SIEM for long-term security analytics and hunting.
- Requirements & Capacity Planning: Define precise data specifications and proactively plan for capacity changes across streaming, routing, indexing, and storage infrastructure.
- Governance & Standards: Assist in developing, documenting, and enforcing comprehensive data ingestion standards, parsing policies, and retention procedures across all supported platforms.
- Actionable Insights: Analyze diverse data sources across the data stack to uncover trends, improve data quality, and provide actionable recommendations to the security operations team.
- Metrics Automation: Develop standards and implement robust automations for metrics aggregation and dissemination, pulling key telemetry from the SIEM and data warehouses.
Qualifications
- Bachelor's Degree with 5 years' experience; or Master's Degree with 4 years' experience
- Experienced in writing and optimizing Splunk’s Search Processing Language (SPL)
- Proven ability to administer Splunk Enterprise and onboard data sources
- Skills in developing data models, dictionaries, and reports within a SIEM platform
- Experience building and configuring data pipelines
- Experience with regular expressions and parsing unstructured data
- Deep understanding of data administration and data standardization policies
- Knowledge of database management systems, query languages, table relationships, and views
- Experience in validating data sets and calculations
- Ability to work both independently without direction and within a group for day-to-day activities
- Capable of learning new concepts and processes quickly, and adapting to a constantly changing environment
- Experience with CI/CD Pipelines and Git
- Experience with database & system integration technologies
- Splunk Certified Admin, Power User, or Architect certification preferred
- Prior experience working in an Agile team
- Familiarity with cybersecurity, privacy principles, cyber threats, and vulnerabilities
- Prior experience working with ETL in a SIEM environment (ELK, Splunk, Exabeam, etc.)
- Experience working with development tools and scripting languages (Python / PowerShell / Go)
- Experience analyzing and pivoting on large sets of data, with the ability to identify patterns, anomalies, and outliers
- Demonstrated experience in log analysis and parsing of unstructured data (ETL)
- Amazon Solutions Architect / Azure Data Engineer Associate / Cloud Professional Data Engineer Certification preferred
Benefits
AbbVie offers a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance, and a 401(k) to eligible employees. This job is eligible to participate in our short-term incentive programs.
Additional Information
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law.
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.