Haystack
← Back to Jobs
Technology
RT

SIEM Engineer - Splunk, Cribl, Exabeam, Sentinel

Request Technology, LLCChicago, IL🇺🇸United StatesPosted 17 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Chicago, IL, United States
Posted
1 week ago
AWSSplunkAzureGoogle CloudPython

Job Description

***We are unable to sponsor as this is a permanent full-time role***

***Hybrid, 3 days onsite, 2 days remote***

Responsibilities:

  • Assist in the implementation, administration, and ongoing optimization of the Firm s SIEM platform (e.g., Google Security Operations (SecOps), Splunk, Exabeam, Microsoft Sentinel).
  • Support the design and maintenance of Cribl pipelines, including data routing, filtering, enrichment, and performance optimization.
  • Build and maintain integrations for standard and custom log sources using APIs, agents, syslog, and cloud-native logging services.
  • Partner with Cybersecurity Operations to develop and refine SIEM use cases, correlation rules, and alerting logic.
  • Create and enhance dashboards, searches, and reports to support SOC (Security Operations Center) operations and threat hunting.
  • Contribute to documentation of SIEM architecture, data flows, onboarding processes, and operational procedures.
  • Help establish and monitor data quality standards to ensure reliable and accurate telemetry.
  • Provide support during security incidents, assisting with investigation and analysis efforts.
  • Stay current on SIEM technologies, security analytics, and observability trends to enhance capabilities.

Qualifications

  • Bachelor s degree or equivalent professional experience required.
  • Minimum of 3 5 years in IT or engineering, with at least 2 3 years focused on SIEM, logging, or security analytics.
  • Hands-on experience working with SIEM platforms such as Google SecOps (Chronicle), Splunk, Exabeam, or Microsoft Sentinel.
  • Experience working with Cribl, including pipeline configuration and log onboarding, preferred.
  • Familiarity with integrating log sources using APIs, syslog, or agents.
  • Experience building dashboards, alerts, and queries to support security monitoring and operations.
  • Understanding of common log sources, including endpoint, network, identity, cloud, SaaS (Software as a Service), and application logs.
  • Exposure to scripting or query languages (e.g., SPL, KQL, Python, Regex) and cloud platforms (Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (Google Cloud Platform)) is a plus.

Similar jobs