Data Analytics Engineer - #2162526
INTEC SELECT LIMITED
Date: 1 hour ago
City: London
Salary:
£550
-
£650
/ day
Contract type: Full time
Data Analytics Engineer
Job Overview
We are seeking an experienced Data Analytics Engineer to lead the migration, optimization, and secure operation of our log ingestion and observability pipelines. The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high availability for log infrastructure.
Key Responsibilities
End-to-End SIEM Pipeline Management & Optimization
Lead the migration of log sources from Splunk ingestion to Cribl Stream/Edge pipelines, ensuring load-balanced, fault-tolerant delivery and processing of security and IT logs.
Architect and manage scalable, resilient pipelines—including design, implementation, and operation of load balancing solutions (e.g., Cribl worker groups, external load balancers, or syslog load distribution) for high ingest volumes.
Analyze, tune and securely onboard all log sources (firewalls, EDR, cloud, authentication, proxies, etc.)—covering parsing, filtering, and data reduction techniques to minimize Splunk ingest/storage costs without sacrificing security coverage.
Develop and maintain Cribl and Splunk configurations, including advanced transformations, field normalization, masking, and enrichment for security analytics.
Ensure optimal distribution of logging workload across Cribl worker nodes and Splunk indexers to prevent bottlenecks, data loss, or single points of failure.
Security Event Visibility and SOC Enablement
Collaborate with SOC, IR, and threat detection teams to ensure all security logs reach the SIEM efficiently and reliably, and logs are tuned for actionable detection.
Actively monitor, test, and remediate pipeline balancing and ingestion health to maximize uptime and forensic visibility.
Respond to and resolve SIEM and pipeline issues that impact security, detection, or compliance visibility.
Governance, Compliance & Documentation
Apply and document security policies for log routing, load balancing, event retention, and integrity—ensuring pipeline architecture meets audit, legal, and privacy requirements.
Track and report ingest reduction, Splunk cost savings, pipeline health, and event loss/drop rates across the load-balanced infrastructure.
Maintain clear, up-to-date documentation of log flows, pipeline topology, load balancing strategies, and operational procedures.
Required Skills & Qualifications
Extensive hands-on experience with Splunk SIEM engineering (indexers, search heads, clustering, forwarders, CIM, performance/load optimization).
2+ years with Cribl Stream/Edge, including deployment and tuning of distributed, load-balanced pipelines.
Deep understanding of machine data transport (syslog, HEC, TCP, UDP), log balancing strategies (syslog balancers, DNS round-robin, Cribl worker groups, etc.), and high-availability logging environments.
Proven expertise onboarding, parsing, and tuning security log sources (firewalls, cloud, EDR/XDR, IAM, authentication, and networking) for best possible coverage and SOC/IR support.
Advanced Splunk SPL, data model, event parsing, and alert tuning skills; practical SIEM optimization experience.
Scripting/automation ability (Python, shell/CLI, or similar) for pipeline management and validation.
Strong troubleshooting, monitoring, and operational dashboard skills for both pipeline and SIEM health.
Preferred Qualifications
Hands-on experience designing and operating clustered/HA Cribl and Splunk deployments (worker groups, clustered indexers, resilient data forwarders, etc.).
Splunk ES or Cribl certifications.
Key Success Metrics
No loss of security data or alert coverage during/after pipeline migration and optimization.
Documented, measurable reductions in Splunk ingest volume and operational/storage cost.
Consistently balanced log throughput and minimal risk of bottlenecks or overloads—pipeline health and reliability metrics maintained above SLA.
Well-documented, adaptable pipeline and load balancing architecture
Job Overview
We are seeking an experienced Data Analytics Engineer to lead the migration, optimization, and secure operation of our log ingestion and observability pipelines. The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high availability for log infrastructure.
Key Responsibilities
End-to-End SIEM Pipeline Management & Optimization
Lead the migration of log sources from Splunk ingestion to Cribl Stream/Edge pipelines, ensuring load-balanced, fault-tolerant delivery and processing of security and IT logs.
Architect and manage scalable, resilient pipelines—including design, implementation, and operation of load balancing solutions (e.g., Cribl worker groups, external load balancers, or syslog load distribution) for high ingest volumes.
Analyze, tune and securely onboard all log sources (firewalls, EDR, cloud, authentication, proxies, etc.)—covering parsing, filtering, and data reduction techniques to minimize Splunk ingest/storage costs without sacrificing security coverage.
Develop and maintain Cribl and Splunk configurations, including advanced transformations, field normalization, masking, and enrichment for security analytics.
Ensure optimal distribution of logging workload across Cribl worker nodes and Splunk indexers to prevent bottlenecks, data loss, or single points of failure.
Security Event Visibility and SOC Enablement
Collaborate with SOC, IR, and threat detection teams to ensure all security logs reach the SIEM efficiently and reliably, and logs are tuned for actionable detection.
Actively monitor, test, and remediate pipeline balancing and ingestion health to maximize uptime and forensic visibility.
Respond to and resolve SIEM and pipeline issues that impact security, detection, or compliance visibility.
Governance, Compliance & Documentation
Apply and document security policies for log routing, load balancing, event retention, and integrity—ensuring pipeline architecture meets audit, legal, and privacy requirements.
Track and report ingest reduction, Splunk cost savings, pipeline health, and event loss/drop rates across the load-balanced infrastructure.
Maintain clear, up-to-date documentation of log flows, pipeline topology, load balancing strategies, and operational procedures.
Required Skills & Qualifications
Extensive hands-on experience with Splunk SIEM engineering (indexers, search heads, clustering, forwarders, CIM, performance/load optimization).
2+ years with Cribl Stream/Edge, including deployment and tuning of distributed, load-balanced pipelines.
Deep understanding of machine data transport (syslog, HEC, TCP, UDP), log balancing strategies (syslog balancers, DNS round-robin, Cribl worker groups, etc.), and high-availability logging environments.
Proven expertise onboarding, parsing, and tuning security log sources (firewalls, cloud, EDR/XDR, IAM, authentication, and networking) for best possible coverage and SOC/IR support.
Advanced Splunk SPL, data model, event parsing, and alert tuning skills; practical SIEM optimization experience.
Scripting/automation ability (Python, shell/CLI, or similar) for pipeline management and validation.
Strong troubleshooting, monitoring, and operational dashboard skills for both pipeline and SIEM health.
Preferred Qualifications
Hands-on experience designing and operating clustered/HA Cribl and Splunk deployments (worker groups, clustered indexers, resilient data forwarders, etc.).
Splunk ES or Cribl certifications.
Key Success Metrics
No loss of security data or alert coverage during/after pipeline migration and optimization.
Documented, measurable reductions in Splunk ingest volume and operational/storage cost.
Consistently balanced log throughput and minimal risk of bottlenecks or overloads—pipeline health and reliability metrics maintained above SLA.
Well-documented, adaptable pipeline and load balancing architecture
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Senior Interior Designer
Appcast Enterprise,
15 minutes ago
JLL empowers you to shape a brighter way . Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring...
Workplace Experience Ambassador
Appcast Enterprise,
15 minutes ago
JLL empowers you to shape a brighter way . Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring...
FP&A Manager
Hays Specialist Recruitment Limited,
£75,000
-
£85,000
/ year
1 hour ago
Your new company I am currently partnering with an exciting retail organisation who are growing their international presence and are looking for an experienced Financial Planning & Analysis manager to join their fast-paced and growing brand. Your new role Key...