SIGN IN
Cyber Data Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Deloitte · 2 hours ago

Cyber Data Engineer

Deloitte is a leading professional services firm that specializes in cybersecurity solutions. They are seeking a Cyber Data Engineer to design, build, and operate security data pipelines, ensuring reliable data collection and integration across various platforms to enhance security analytics and incident response capabilities.
AccountingConsultingFinancial ServicesLegalProfessional ServicesRisk Management
check
Growth Opportunities
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Engineer and maintain security data pipelines (Cribl and/or equivalent) for ingestion, parsing, enrichment, filtering, routing, and delivery to ELM/SIEM and related platforms
Integrate event feeds using common transport patterns (e.g., syslog) and validate end-to-end data flow, timing, completeness, and correctness
Implement data transformations and normalization to support analytics and detection use cases (e.g., consistent fields, time alignment, source attribution)
Operate and troubleshoot pipeline services, including performance tuning, backlog/latency reduction, and resilience/high-availability considerations
Collaborate with SIEM/ELM engineers, SOC (Security Operations Center) teams, and system owners to support onboarding, use-case enablement, and ongoing data quality improvements
Support detection and incident response automation by ensuring required data elements are present, consistent, and delivered to the right destinations
Create and maintain documentation (architecture/data flow diagrams, pipeline configurations, onboarding guides, SOPs, and troubleshooting runbooks)
Participate in change control processes: implementation planning, testing/validation, and post-deployment verification

Qualification

CriblSIEMData pipelinesData transformationEvent feeds integrationScripting/automationData governanceCloud environmentsOn-premises environmentsSplunkCrowdStrike FalconTechnical writingProblem-solving

Required

Bachelor's degree
Ability to obtain Public Trust clearance
Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
4+ years of experience in at least five or more of the following:
Managing and engineering data pipelines (Cribl preferred; equivalent tools accepted)
Solid experience with SIEM ingestion, data transformation, and platform integration
Hands-on experience integrating event feeds with ELM/SIEM systems using syslog (and related patterns)
Proven ability to create and maintain pipeline and deployment documentation
Knowledge of threat/incident detection automation concepts in ELM/SIEM contexts (e.g., ensuring telemetry supports correlation and alerting)
Working knowledge of Splunk and familiarity with CrowdStrike Falcon platform features
Familiarity with both cloud and on-premises data environments
Strong problem-solving skills, technical writing/documentation discipline, and effective cross-team communication
Experience with data governance for security telemetry (data quality checks, schemas/standards, retention considerations)
Scripting/automation experience to support pipeline operations and repeatable deployments
Experience supporting high-volume telemetry and multiple downstream destinations (security analytics, storage, compliance reporting)

Preferred

Cribl

Benefits

Discretionary annual incentive program

Company

Deloitte

company-logo
Deloitte is a business consulting company that offers audit, consulting, financial advisory, and tax services.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Anne Muraya
Chief Executive Officer - East Africa
linkedin
leader-logo
Joe Ucuzoglu
Global Chief Executive Officer
linkedin
Company data provided by crunchbase