About the role
Role Description Title: CyberTech Engineer Location: Irving, Tx (Hybrid) This role requires a senior BFT CyberTech Engineer with deep handson expertise in modern cloudnative security platform engineering spanning SIEM data pipeline data lake and SOAR technologies The consultant will be a critical technical contributor in delivering a Unified AIDriven SOC capability a federated broadcapability query and orchestration system that unifies SOC operations threat intelligence log management incident case management and broader security data underpinned by a configurable AI agent layer for incident and event investigation
Key Responsibilities
- Cloud Native SIEM Engineering
- Architect deploy and operate modern cloudnative SIEM platforms eg Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent at enterprise scale
- Design and implement federated query capabilities enabling broad crossdomain search across SOC intelligence log management and case management data sources
- Develop and maintain detection content correlation rules and dashboards aligned to SOC operational requirements and threat use cases
- Optimize SIEM performance data tiering and retention strategies to balance cost coverage and query fidelity
- Data Pipeline Engineering Cribl
- Design build and manage enterprisegrade data pipelines using Cribl Stream andor Cribl Edge for log routing enrichment transformation filtering and normalization at scale
- Implement Criblbased data management strategies to optimize data volume reduce ingest costs and ensure highfidelity event delivery to SIEM and data lake destinations
- Develop Cribl pipelines that support multidestination routing across SIEM data lake and cold storage tiers
- Collaborate with detection engineering and threat intelligence teams to enrich pipeline data with contextual security signals
- Security Data Lake Engineering
- Architect and manage a scalable cloudnative security data lake eg on AWS S3Athena GCP BigQuery or Snowflake for longterm log retention threat hunting and AIML workloads
- Develop data models schemas and partitioning strategies optimized for security analytics and federated query performance
- Enable broadcapability query access across SOC intel and incident data stored within the data lake supporting both realtime and retrospective investigation workflows
- Integrate data lake telemetry with SIEM and SOAR platforms to support unified investigation and orchestration
- SOAR Platform Engineering
- Design deploy and maintain SOAR platform infrastructure eg Palo Alto XSOAR Splunk SOAR Google SecOps SOAR or equivalent to enable automated incident response and orchestration workflows
- Build and maintain SOAR playbooks and integrations that span SOC case management threat intelligence SIEM ing and external security tooling
- Engineer orchestration workflows that leverage AI agent capabilities for automated event triage enrichment and investigation recommendations
- Continuously improve SOAR operational efficiency through playbook tuning integration maintenance and metricdriven optimization
- AIDriven SOC Enablement
- Contribute to the design and implementation of a configurable AI agent layer for incident and event investigation integrating with SIEM SOAR data lake and case management systems
- Engineer the data and API connectivity required to support AI agent queries context retrieval and automated investigation workflows across federated SOC data sources
- Collaborate with data science AIML engineering and detection engineering teams to operationalize AIdriven investigation and triage capabilities within the SOC platform
- Support the evaluation and integration of emerging AIGenAI security operations tooling aligned to the unified SOC vision
- Platform Integration Federated Architecture
- Design and implement integration patterns that connect SIEM data pipeline data lake SOAR and case management platforms into a cohesive federated SOC data fabric
- Develop and maintain APIs webhooks and data connectors to ensure seamless interoperability across the SOC technology ecosystem
- Apply cloudnative engineering best practices IaC CICD containerization to SOC platform deployment configuration management and operational scaling
Required Skills Experience
- Experience 7 years in cybersecurity or security platform engineering with demonstrable handson experience across SIEM data pipeline data lake and SOAR technologies in enterprise environments
- SIEM
- Deep expertise in one or more modern cloudnative SIEM platforms Google Chronicle Microsoft Sentinel Elastic SIEM or equivalent
- Experience with federated search data normalization eg UDM OCSF and largescale detection content management
- Data Pipeline Cribl Required
- Strong handson proficiency with Cribl Stream andor Cribl Edge for enterprise log management routing enrichment and transformation
- Experience designing multidestination Cribl pipelines across SIEM data la
Other Details Actual compensation within the range will be dependent upon the individual's skills, experience, performance and internal equity.
Benefits/perks listed below may vary depending on the nature of your employment with LTIMindtree (“LTIM”):
Benefits And Perks
- Comprehensive Medical Plan Covering Medical, Dental, Vision
- Short Term and Long-Term Disability Coverage
- 401(k) Plan with Company match
- Life Insurance
- Vacation Time, Sick Leave, Paid Holidays
- Paid Paternity and Maternity Leave
The range displayed on each job posting reflects the minimum and maximum salary target for the position across all US locations. Within the range, individual pay is determined by work location and job level and additional factors including job-related skills, experience, and relevant education or training. Depending on the position offered, other forms of compensation may be provided as part of overall compensation like an annual performance-based bonus, sales incentive pay and other forms of bonus or variable compensation.
Disclaimer : The compensation and benefits information provided herein is accurate as of the date of this posting.
LTIMindtree is an equal opportunity employer that is committed to diversity in the workplace. Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnancy, childbirth or related medical conditions), gender identity or expression, national origin, ancestry, age, family-care status, veteran status, marital status, civil union status, domestic partnership status, military service, handicap or disability or history of handicap or disability, genetic information, atypical hereditary cellular or blood trait, union affiliation, affectional or sexual orientation or preference, or any other characteristic protected by applicable federal, state, or local law, except where such considerations are bona fide occupational qualifications permitted by law.
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at LTM was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
