
Engineer II – SIEM Integrations
CrowdStrike20 hours ago
Bengaluru, IndiaMid Level
Responsibilities
- Evaluate, develop, maintain, and enhance data connectors and parsers for ingesting third-party security product data into CrowdStrike Next-Gen SIEM.
- Set up and maintain test environments for security products to validate connectors and troubleshoot issues.
- Troubleshoot existing data connectors and resolve data ingestion problems and production incidents, including through on-call support.
- Collaborate on logging, error handling, data normalization, and connector documentation.
- Research and implement security log ingestion practices for firewalls, IDS/IPS, cloud security, endpoint security, and other security products.
- Write technical documentation and troubleshooting guides.
- Work with customers, customer success, and customer support teams to resolve data ingestion issues and communicate effectively.
Requirements
- Bachelor’s or master’s degree in computer science or a related field, or equivalent work experience.
- At least 4 years of experience in cybersecurity and SIEM integrations.
- Experience developing data connectors or ingestion pipelines for SIEM platforms such as Splunk, Sentinel, Exabeam, and QRadar.
- Experience with security data normalization schemas, parsing, and data enrichment.
- Experience setting up and managing firewall, IDS/IPS, EDR, CASB, identity security, and email security environments.
- Experience with security event formats including Syslog, CEF, LEEF, JSON, and XML.
- Working knowledge of Cribl, Splunk Forwarder, Azure Monitoring Agent, LogScale Log Collector, or similar tools.
- Proficiency in at least one programming language, preferably Python or Go.
- Strong documentation, communication, and customer interaction skills.
- Proven experience using AI technologies to improve decision-making, workflows, processes, efficiency, and business outcomes.
- Knowledge of AWS CloudWatch, Azure Monitor, or GCP Logging is a bonus.
Benefits
- Compensation and equity awards, comprehensive physical and mental wellness programs, competitive vacation and holidays, and paid parental and adoption leave.
- Professional development opportunities, employee networks, geographic neighborhood groups, volunteer opportunities, and office amenities.
- Equal opportunity employer with support for veterans and individuals with disabilities.
About CrowdStrike
CrowdStrike builds the Falcon cloud-native security platform used by enterprises and governments to protect endpoints, cloud workloads, identities, and data with EDR, next-generation antivirus, threat intelligence, and managed threat hunting. Founded in 2011 and publicly traded on NASDAQ as CRWD, the company sells primarily by subscription and also provides incident response services; its systems ingest and analyze nearly 3 trillion security events per day across customer environments.