×
Register Here to Apply for Jobs or Post Jobs. X

Senior SIEM​/Data Integration Engineer - Cribl​/Splunk; TS​/SCI

Job in Tampa, Hillsborough County, Florida, 33646, USA
Listing for: Kentro Estelle iLab
Full Time position
Listed on 2026-01-01
Job specializations:
  • Engineering
    Cybersecurity, Data Engineer
Salary/Wage Range or Industry Benchmark: 120000 - 150000 USD Yearly USD 120000.00 150000.00 YEAR
Job Description & How to Apply Below
Position: Senior SIEM/Data Integration Engineer - Cribl/Splunk (TS/SCI)

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Kentro is seeking a highly skilled and motivated SIEM/Data Integration Engineer to design, build, and manage the critical telemetry pipeline for a landmark Zero Trust initiative at U.S. Special Operations Command (USSOCOM). This role is the lynchpin for security visibility, ensuring that the high-volume, complex data generated by modern security tools is intelligently processed and delivered to security analysts in a timely, cost-effective, and usable format.

Your primary responsibility will be to architect and operate the Cribl Stream environment, creating an intelligent data pipeline that sits between the cloud-native security tools (Microsoft Purview, Microsoft Sentinel) and the enterprise Splunk SIEM. You will be the technical expert responsible for ingesting, filtering, transforming, enriching, and routing massive streams of security data across the NIPR, SIPR, and Top Secret networks.

By optimizing the flow of data, you will also play a crucial role in managing the performance and cost of the enterprise SIEM, ensuring the long-term sustainability of the Command's security monitoring capabilities.

Responsibilities
  • Telemetry Pipeline Architecture:
    Design, deploy, and maintain the Cribl Stream infrastructure, ensuring high availability and performance for the security telemetry pipeline across all network enclaves.
  • Data Routing & Filtering:
    Develop and manage Cribl Stream routes to process security data, implementing rules to filter out low-value logs and route high-value telemetry to Splunk and Microsoft Sentinel.
  • Data Integration:
    Configure data source collectors to ingest logs from Microsoft Purview, Microsoft Sentinel, and on-premise security tools, utilizing APIs (such as Microsoft Graph) to pull compliance data.
  • Log Enrichment:
    Enrich security logs in-flight by adding valuable context, such as correlating user identity information with network events or adding geolocation data, before the data reaches the SIEM.
  • SIEM Optimization:
    Proactively reduce Splunk ingestion volume and license costs by strategically filtering and summarizing data within Cribl Stream, while ensuring that the data delivered aligns with the Splunk Common Information Model (CIM).
Location

Onsite in Tampa, FL

Qualifications
  • Senior Level: Master of Science (MS) degree in Systems Engineering, Computer Science, Cybersecurity, Electrical Engineering, or a related technical field.
  • Senior Level: 10+ years of related technical experience.
  • Splunk Expertise:
    Extensive (5+ years) experience as a Splunk administrator or engineer, with deep expertise in data onboarding, parsing, index-time processing, and search performance optimization.
  • Pipeline Management:
    Direct, hands-on experience (2+ years) designing and managing a telemetry pipeline or log routing solution, with a strong preference for Cribl Stream.
  • Scripting & Automation:
    Proficiency in scripting using languages such as Python or Power Shell for data manipulation and API interaction.
  • Data Parsing:
    Strong understanding of regular expressions (Regex) for complex data parsing, extraction, and normalization.
Preferred Experience & Skills (Nice-to-Haves)
  • Cribl Certified Observability Engineer (CCOE) certification.
  • Splunk certifications such as Splunk Certified Architect or Enterprise Security Certified Admin.
  • Hands-on experience with Microsoft Sentinel and Microsoft Purview as data sources.
  • Experience working in a large, complex DoD or USSOCOM environment.
Certifications
  • Required: CompTIA Security+ CE, CompTIA CySA+, or a higher-level certification to meet DoD 8570 IAT Level II requirements.
  • Preferred: Splunk Core Certified Advanced Power User, Splunk Enterprise Certified Admin/Architect, or…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary