Design, build, and maintain scalable data ingestion pipelines for onboarding security log sources into SIEM and cloud data platforms, including Azure Data Explorer and Log Analytics.
Parse, normalize, transform, and enrich structured and unstructured log data using techniques such as regex, JSON parsing, schema mapping, and data validation.
Partner with application owners, infrastructure teams, cloud teams, vendors, and security stakeholders to onboard new log sources and confirm end-to-end data flow.
Validate log integrity, completeness, timeliness, and quality to ensure security telemetry is reliable and fit for monitoring, detection, response, and reporting use cases.
Align onboarded data to organizational standards, schemas, naming conventions, and data governance expectations to support downstream analytics and automation.
What's Needed?
Minimum of 3 years of relevant experience in cybersecurity, data engineering, log management, or related technology disciplines.
Hands-on experience onboarding, managing, and validating log sources in SIEM, cloud data platforms, or security analytics environments.
Strong understanding of data parsing, normalization, transformation, and validation techniques, including regex, JSON, XML, CSV, and handling structured and unstructured data.
Familiarity with common security telemetry sources, including network, endpoint, identity, application, cloud, and infrastructure logs.
Experience with cloud platforms and associated logging, monitoring, and analytics services