Haystack
← Back to Jobs
Engineering

Cribl Engineer with Palo Alto experience

iCUBE SolutionsUnited States🇺🇸United StatesPosted 5 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Cribl Engineer

Remote

6 Months

Job Description:

Position Overview

We are seeking a highly skilled Cribl Resident Engineer to serve as the dedicated technical expert supporting the integration, optimization, and ongoing operations of the Cribl platform within a Palo Alto Networks security ecosystem. This consultant will work closely with security, network, and platform engineering teams to design, implement, and support log management, observability, and security telemetry solutions that improve visibility, scalability, and operational efficiency.

The ideal candidate brings deep expertise in Cribl Stream, Cribl Edge, and log pipeline engineering, combined with hands-on experience integrating security tools such as Palo Alto firewalls, Panorama, Prisma Access, and SIEM platforms.

Key Responsibilities

Cribl Platform Engineering

  • Design, deploy, configure, and administer Cribl Stream and related Cribl components.
  • Develop and optimize log routing, filtering, enrichment, transformation, and forwarding pipelines.
  • Ensure high availability, scalability, and performance of Cribl infrastructure.
  • Perform upgrades, troubleshooting, health checks, and operational support.

Palo Alto Integration

  • Integrate Cribl with Palo Alto security solutions, including:
    • Palo Alto Next-Generation Firewalls (NGFW)
    • Panorama
    • Prisma Access
    • Strata Cloud Manager
  • Design and optimize log ingestion workflows from Palo Alto platforms into SIEM and observability tools.
  • Validate telemetry collection and ensure critical security events are properly normalized and enriched.
  • Support security operations teams with log visibility, threat detection, and incident response requirements.

Security Logging & SIEM Enablement

  • Integrate Cribl with enterprise security tools such as:
    • Splunk
    • Microsoft Sentinel
    • Elastic
    • Other SIEM and monitoring platforms
  • Implement log reduction, cost optimization, and intelligent data routing strategies.
  • Create dashboards, monitoring, alerting, and operational runbooks.

Automation & Optimization

  • Develop automation workflows using:
    • REST APIs
    • Python
    • PowerShell
    • Infrastructure-as-Code methodologies
  • Streamline onboarding of new log sources and security platforms.
  • Improve logging efficiency, data quality, and operational workflows.

Collaboration & Advisory

  • Act as the resident subject matter expert for Cribl and logging architecture.
  • Partner with security, network, cloud, and infrastructure teams.
  • Provide knowledge transfer, documentation, and best-practice guidance.
  • Participate in architecture reviews, troubleshooting sessions, and operational planning activities.

Required Qualifications

  • 5+ years of experience in Security Engineering, SIEM Engineering, or Observability Engineering.
  • 3+ years of hands-on experience with Cribl Stream.
  • Experience integrating Cribl with enterprise security and observability platforms.
  • Strong experience with Palo Alto technologies:
    • NGFW
    • Panorama
    • Prisma Access
    • Strata Cloud Manager
  • Knowledge of security logging, event management, and telemetry pipelines.
  • Experience with SIEM tools such as Splunk or Microsoft Sentinel.
  • Strong understanding of:
    • Syslog
    • TCP/IP
    • Network Security
    • Security Architecture
    • Log Management
  • Experience with REST APIs and scripting languages such as Python or PowerShell.

Similar jobs