Senior Platform Operations Engineer
Listed on 2026-07-16
-
IT/Tech
Cybersecurity
Sr. Platform Operations Engineer
State Street's Cyber Data & Analytics (CyberDNA) team is seeking a Sr. Platform Operations Engineer to help shape the next generation of cybersecurity data, analytics, and AI-powered platforms. Partnering closely with Global Cyber Security, Infrastructure Teams, and Enterprise Continuity Services, this team develops advanced data platforms, intelligent automation solutions, and engineering capabilities that enable cybersecurity teams to make faster, data-driven decisions and strengthen the firm's ability to detect, prevent, and respond to evolving cyber threats.
Through innovation in AI, analytics, and automation, CyberDNA plays a critical role in protecting State Street, its clients, and its partners from increasingly sophisticated global threat actors.
The ideal candidate brings strong operational discipline, hands-on platform support experience, and the ability to lead globally distributed teams supporting high-availability cybersecurity, SIEM, observability, log management, and security operations platforms in a large enterprise environment. The ideal candidate supports the operational reliability, administration, monitoring, troubleshooting, and continuous improvement of enterprise cybersecurity and SIEM platforms, including tools such as Splunk, QRadar, Elastic, and similar security operations technologies.
This hands-on support leadership role will focus on production support, incident handling, user support, operational readiness, change management, ITIL processes, SOP adherence, and reporting of operational metrics in a large enterprise environment.
What You Will Be Responsible For
- Lead the support, administration, reliability, and day-to-day operations of enterprise cybersecurity, SIEM, observability, log management, and data platforms.
- Support the operational roadmap for cybersecurity platform capabilities, including SIEM operations, detection support, observability, log monitoring, data ingestion, and reporting across the organization.
- Support platform modernization and operational improvement initiatives across cybersecurity platforms, SIEM technologies, observability solutions, log management capabilities, and security operations tooling.
- Provide technical leadership and mentorship for global support teams responsible for enterprise cybersecurity platforms, SIEM technologies, observability solutions, log management platforms, data ingestion pipelines, and operational analytics capabilities, including tools such as Splunk, Enterprise Security, Elastic Search, Cribl, Databricks, and similar security operations platforms.
- Manage and support enterprise SIEM and cybersecurity platform components, including search, indexing, clustering, data management, platform integrations, and operational support functions across tools such as Splunk, Elastic Search, and other SIEM technologies.
- Administer and optimize SIEM and security operations capabilities to support security monitoring, threat detection, alert triage, notable event management, and incident investigation requirements across enterprise cybersecurity platforms.
- Optimize platform operations by using monitoring alerts, performance trends, service metrics, and operational insights to improve reliability, reduce recurring issues, lower technical debt, and strengthen service resiliency.
- Lead platform upgrades, migrations, modernization initiatives, and service improvement programs.
- Support enterprise log pipeline and telemetry management platforms, including tools such as Cribl, by monitoring data flow, troubleshooting routing or filtering issues, validating service health, and coordinating issue resolution with application and infrastructure teams.
- Support integration of security and operational telemetry into Databricks Data Lake environments for analytics, reporting, and long-term data retention.
- Monitor ingestion health, data quality, storage utilization, platform performance, and service availability across SIEM, log management, telemetry pipeline, and data platform environments.
- Partner with Cyber Security, Infrastructure, Cloud Engineering, Application, and Service Management teams to support production issues, troubleshoot platform events, coordinate change activities, and deliver stable operational outcomes.
- Hands-on experience with Anvilogic and Crogl or similar SIEM detection engineering platforms for detection engineering, SIEM use case development, alert workflow support, and threat detection operations.
- Improve operational support workflows for alerting, monitoring, telemetry pipeline health, incident response, and observability use cases to reduce manual effort and improve service reliability.
- Lead incident response, root cause analysis, problem management, change execution, and continuous improvement activities.
- Define, implement, and continuously improve operational standards, governance, documentation, monitoring procedures, SOPs, and support models aligned to ITIL, change management, and log telemetry monitoring…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).