
Senior Security Data Engineer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Take ownership of multi-terabyte-per-day log pipelines across AWS and GCP, encompassing ingestion, routing, enrichment, schema management, and the integration of new sources.
• Manage ingestion costs and volumes while ensuring the preservation of audit logs required by investigators.
• Model security data and optimize query performance in Snowflake, BigQuery, and Redshift.
• Deliver production services and integrations, which include custom SIEM connectors, API clients, and automation solutions.
• Establish and uphold SLOs for log availability and freshness.
• Develop dashboards and alert systems for monitoring service-level objectives.
• Oversee infrastructure as code and CI/CD processes, including the deployment pathways for detections-as-code.
• Create AI agents and automated runbooks to enhance triage and remediation across cloud infrastructures.
• Implement IAM and service account governance for cloud workloads.
• Lead cross-functional initiatives spanning infrastructure, platform engineering, and incident response.
• Develop and maintain standards and documentation.
• Mentor engineers within the Cyber Defense team.
• Engage in an on-call rotation to ensure pipeline health.
• Collaborate consistently with teams in IT, legal, privacy, incident response, insider risk, threat intelligence, and detection engineering.
• A minimum of 5 years of experience building and operating high-volume data pipelines in production at a scale of multi-terabytes per day, utilizing tools such as Kafka, Cribl, Dataflow, Kinesis, or CloudWatch.
• At least 4 years of experience in writing production software using Python, Go, Rust, or Java.
• Extensive hands-on experience with AWS and GCP.
• Proficiency in infrastructure as code and CI/CD pipelines on platforms like GitHub, GitLab, or Bitbucket.
• Strong skills in SQL and data modeling within a columnar warehouse, including Snowflake, BigQuery, or Redshift.
• Experience in partitioning, cost management, and query optimization.
• Proven track record of owning reliability for a platform, including participation in on-call duties.
• Experience in creating executive dashboards and engineering metrics.
• Demonstrated leadership and technical project management capabilities across infrastructure, platform engineering, and incident response.
• Exceptional written and verbal communication skills, along with a collaborative mindset and a commitment to continuous learning.
• Familiarity with enterprise SIEM solutions such as Google SecOps/Chronicle, Splunk, Elastic, or CrowdStrike LogScale is advantageous.
• Knowledge of Kubernetes, Docker, and runtime security controls is a plus.
• Hands-on experience with security telemetry sources, detections-as-code (YARA-L, Sigma, SPL), LLM-assisted workflows, penetration testing, red teaming, or triaging bug bounty reports is beneficial.
• Equity grants
• 401(k) plan with employer matching
• 16 weeks of paid parental leave
• Wellness benefits
• Commuter benefits match
• Paid time off
• Paid sick leave
• Medical benefits
• Dental benefits
• Vision benefits
• 11 paid holidays
• Disability insurance
• Basic life insurance
• Family-forming assistance
• Mental health program
• Flexible paid time off/vacation for salaried roles
• 80 hours of paid sick time per year for salaried roles
• Wellness expense reimbursement
• Premium healthcare
• Accommodations for applicants with disabilities
Magna Legal Services
Huron
Strategic Systems International
Get handpicked remote jobs straight to your inbox weekly.