Job Openings CRIBL & Snowflake Developer

About the job CRIBL & Snowflake Developer

As a CRIBL & Snowflake Developer, you will architect, build, and maintain high‑volume, high‑fidelity security data management solutions using Cribl (ETL) and Snowflake (Data Lakehouse) platforms to support SIEM, SOAR, UEBA, and detection engineering use cases. You will lead ingestion, normalization, enrichment, and correlation of raw security telemetry, enforce data standards, and partner with security teams to deliver scalable, reliable, and cost‑efficient data solutions.

What You'll Do and How You'll Succeed

Data Engineering & Architecture

  • Architect and maintain security data pipelines using Cribl and Snowflake.
  • Lead ingestion, normalization, enrichment, and correlation of raw telemetry (logs, events, metrics, alerts, configs, scanning data).
  • Define and enforce schemas and normalization frameworks across OCSF, STIX, SCIM, OWASP OPTRS, CVE/CVSS formats.
  • Manage data governance, reporting, and quality checks.

Analytics & Integration

  • Leverage SQL, Python, and PowerBI to design analytics and reporting solutions.
  • Partner with Security Operations, Threat Detection, GRC, and engineering teams to translate requirements into scalable solutions.
  • Serve as a technical authority and mentor, influencing platform strategy and security analytics.
  • Research and adopt best practices, industry standards, and emerging technologies.

Continuous Improvement & Documentation

  • Drive improvements in data reliability, performance, and cost efficiency.
  • Produce engineering, integration, and process documentation.
  • Conduct POCs of new features to develop innovative solutions.
  • Manage vendor relationships for roadmap, design, implementation, and troubleshooting.

We'd Love to Hear From You If...

Experience

  • You have 10+ years of database engineering experience with a focus on security data.
  • You have 8+ years of hands‑on experience with databases (Snowflake, SQL, NoSQL).
  • You have 2+ years of experience with data warehouses/lakes (Snowflake, Databricks, BigQuery, Redshift, Azure Synapse).
  • You have 1+ years of experience with reporting tools (PowerBI, Tableau).

Technical Expertise

  • You are familiar with SIEM products (Splunk, Cribl, Elastic, Datadog, AWS CloudTrail, Azure Event Hub).
  • You have experience with streaming platforms (Cribl, Kafka, Kinesis).
  • You have strong programming skills in Python, SQL, Java, or JavaScript.
  • You are skilled in ETL/ELT pipelines, data modeling, normalization, schema design, and governance.
  • You have experience with AI/ML technologies (Anthropic, ChatGPT, Gemini, Copilot).
  • You are familiar with industry standards (OCSF, SCIM, STIX, OWASP OPTRS) and frameworks (MITRE ATT&CK, CRI).
  • You have experience with at least one major cloud provider (AWS, Azure, GCP).

Ways of Working

  • You are analytical, detail‑oriented, and proactive in problem‑solving.
  • You collaborate effectively with cross‑functional teams and vendors.
  • You are comfortable working with large‑scale datasets (batch and streaming).
  • You are disciplined in documentation, governance, and compliance.

Education & Certifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience).
  • Preferred certifications: CISSP, CISM, CISA, CEH.