Overview
Engineer II focused on SIEM integrations, building and maintaining out-of-the-box data connectors and parsers for CrowdStrike Next-Gen SIEM.
What you'll do
- Develop, maintain, and enhance data connectors and parsers for ingesting third-party security data into CrowdStrike Next-Gen SIEM.
- Set up and maintain lab/test environments to validate connectors and troubleshoot ingestion issues.
- Troubleshoot and resolve problems with existing connectors to ensure reliable log ingestion.
- Collaborate on logging, error handling, data normalization, and documentation for connectors.
- Research and implement best practices for ingesting security logs from multiple security product categories.
- Write and maintain technical documentation, including integration methods and troubleshooting guides.
- Provide on-call support for critical ingestion issues and production incidents.
What you'll need
- 4+ years of experience in cybersecurity and SIEM integrations.
- Hands-on experience in data ingestion pipelines, log collection mechanisms, and security event processing.
- Experience building data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, or QRadar.
- Knowledge of security data normalization schemas, parsing, and data enrichment.
- Experience setting up and managing environments for security products including Firewalls, IDS/IPS, EDR, CASB, Identity Security, and Email Security.
- Experience with security event formats such as Syslog, CEF, LEEF, JSON, and XML.
- Knowledge of log processing/shipping tools such as Cribl, Splunk forwarder, Azure monitoring agent, or LogScale log collector.
- Proficiency in at least one programming language, preferably Python or Go.
- Strong documentation, communication, and customer interaction skills.
Nice to have
- Knowledge of cloud-native logging services such as AWS CloudWatch, Azure Monitor, or GCP Logging.
Details
- Location: India - Bangalore.
Read the full description and apply on the company’s own careers page.