Enter a job title or keyword

Security Architect – Consultant – Data Modeling Engineer (Cribl)


Job Location:

Columbia, IN - USA

Monthly Salary: Not provided by the employer
Posted: 30 September 2026 (5 hours ago)
Application Deadline: 28 December 2026
Vacancies: 1 Vacancy

Job Summary

Cribl data modeling and log-pipeline engineering is the central requirement for this role

Do not move forward with a candidate unless the required hands-on Cribl experience enterprise security engineering experience SIEM experience Python/Bash scripting operating-system security experience rate expectations screening requirements education/experience requirements work-location requirements and required submission documents have been confirmed.

Job Information

  • Working Title: Security Architect Consultant Data Modeling Engineer (Cribl)

  • Category: IT / Cybersecurity

  • Visa: W2 (USC/GC Independent) Locals

This position is 100% remote

  • Location: Columbia South Carolina 29210

  • Preference will be given to the candidates located in or near South Carolina who can occasionally report onsite are preferred.

Position Overview

  • The State of South Carolina is seeking an experienced Security Architect Consultant Data Modeling Engineer with deep hands-on experience using Cribl to design implement and maintain enterprise security-data pipelines.

  • This is not a general cybersecurity architect or SIEM administrator position.

  • The central requirement is hands-on experience with Cribl data modeling log-pipeline design implementation routing transformation and delivery of security telemetry into enterprise SIEM environments.

  • The selected consultant will work alongside full-time security architects and engineers supporting large-scale enterprise cybersecurity initiatives.

  • The role combines Cribl engineering with broader hands-on security engineering across SIEM XDR vulnerability management DLP endpoint security Linux security sensors Windows/Linux security configuration security integrations automation threat detection and defensive security architecture.

  • Automation is also important. Candidates should demonstrate experience building integrations and security automation using scripting languages such as Python and Bash.

  • The strongest candidates will have substantial experience operating within complex enterprise security environments rather than simply having exposure to Cribl or SIEM technologies.

Scope of Project

The selected consultant will support:

Cribl data modeling

Cribl Stream / log-pipeline architecture

Enterprise log ingestion

Security-data routing

Parsing and transformation of security telemetry

Data normalization and enrichment

SIEM data delivery and integration

SIEM administration analysis and reporting

Enterprise security architecture

Security-tool implementation and support

XDR technologies

Vulnerability-management platforms

Data Loss Prevention / DLP

Endpoint security

Linux-based security sensors

Windows and Linux security configuration

Security-system hardening

Cybersecurity automation

Python scripting

Bash scripting

Security integrations

Threat detection

Defensive security strategies

Networking and secure-system design

Security controls and countermeasures

Security-control validation

Incident-detection support

Enterprise cybersecurity engineering

Daily Duties / Responsibilities

The selected candidate will:

Design build implement and maintain Cribl data models and log pipelines

Develop enterprise security-data ingestion and routing workflows

Configure pipelines that deliver security telemetry into enterprise SIEM environments

Perform data parsing filtering transformation enrichment routing and normalization

Work directly with enterprise security architects and engineers

Support SIEM administration analysis and reporting

Implement and support enterprise security technologies

Support XDR platforms

Support vulnerability-management technologies

Support DLP technologies

Support endpoint-security platforms

Build and deploy Linux-based security sensors

Support Linux and Windows security configuration and hardening

Develop security automation and integrations using Python and Bash

Support enterprise threat-detection capabilities

Assist with defensive-security engineering

Support security-control implementation and validation

Participate in enterprise security architecture discussions

Support incident-detection activities

Troubleshoot complex security-data and integration issues

Support secure networking and system-design initiatives

Participate in the required on-call rotation

Required Qualifications

The candidate must have:

Hands-on Cribl data modeling experience

Cribl log-pipeline design and implementation experience

Strong understanding of enterprise security architecture and engineering principles

Experience implementing and supporting enterprise security tools

Security-tool experience should include exposure to technologies such as:

SIEM

XDR

Vulnerability Management

Data Loss Prevention / DLP

Endpoint Security

The candidate must also have:

Experience developing automation and integrations using Python and/or Bash

Knowledge of cybersecurity best practices

Threat-detection experience

Defensive-security knowledge

Linux operating-system experience

Windows operating-system experience

System-hardening experience

Security-configuration experience

Understanding of networking concepts

Understanding of security protocols

Understanding of secure-system design

5 years of experience supporting large IT environments and/or enterprise system deployments

All required experience should be clearly and explicitly documented in the resume.

Do not rely solely on a skills section or broad statements such as:

Cribl

SIEM

Cybersecurity

Security Architecture

Python

The resume should establish what the candidate actually designed configured implemented supported automated integrated or administered.

For Cribl specifically the resume should demonstrate meaningful hands-on responsibility rather than simple platform exposure.

Required Education

The candidate should have:

Bachelors degree in an Information Technology-related field

OR

Bachelors degree in a Security-related field

OR

8 years of relevant professional experience may be substituted in lieu of the degree requirement

Please confirm the candidates education and/or qualifying equivalent experience before submission.

Preferred Qualifications

Preferred experience includes:

Hands-on Cribl data modeling experience

Advanced Cribl Stream experience

SIEM administration

SIEM analysis

SIEM reporting

Building and deploying Linux-based security sensors

Enterprise cybersecurity engineering

Security architecture

Security automation

Security-system integration

NIST Cybersecurity Framework / NIST CSF

CJIS

IRS Publication 1075

CMS MARS-E

Preferred certifications include:

CISSP

Security

The strongest candidates will demonstrate multiple preferred qualifications but hands-on Cribl remains the most important technical signal.

Additional Skills

The candidate should also demonstrate:

Strong enterprise security-engineering capabilities

Strong troubleshooting and analytical skills

Strong technical communication skills

Ability to work with security architects and engineering teams

Ability to design scalable security-data pipelines

Ability to troubleshoot log-ingestion and routing issues

Ability to automate repetitive security-engineering processes

Ability to understand complex security-data flows

Strong Linux skills

Strong Windows-security knowledge

Strong networking fundamentals

Ability to work independently in a remote environment

Ability to participate in an on-call environment

Target Candidate Profile

Focus on candidates with backgrounds such as:

Cribl Engineer

Cribl Stream Engineer

Security Data Engineer

Security Data Pipeline Engineer

SIEM Engineer

Senior SIEM Engineer

Security Engineer

Senior Security Engineer

Security Architect

Cybersecurity Engineer

Security Platform Engineer

Security Automation Engineer

Logging / Telemetry Engineer

Observability Engineer

Detection Engineer

Security Infrastructure Engineer

The strongest candidates will have:

5 years of enterprise IT/security experience

Real hands-on Cribl Stream experience

Cribl data modeling experience

Cribl pipeline-design experience

Log-ingestion experience

Log-routing experience

Parsing and transformation experience

Data normalization experience

Security telemetry experience

Enterprise SIEM experience

SIEM administration or engineering experience

Python scripting experience

Bash scripting experience

Linux security experience

Windows security experience

Security automation experience

Security-tool integration experience

XDR experience

Vulnerability-management experience

DLP experience

Endpoint-security experience

Networking/security-protocol knowledge

Threat-detection experience

Defensive-security experience

Experience supporting large enterprise environments

Especially strong profiles may combine Cribl with SIEM platforms such as:

Splunk

Microsoft Sentinel

IBM QRadar

Elastic / Elasticsearch

Other large-scale enterprise SIEM platforms

Cribl Screening Standard

Treat Cribl as a true knockout requirement.

Do not move forward based solely on a candidate mentioning Cribl in a skills section.

During screening confirm specifically whether the candidate has personally:

Designed Cribl pipelines

Built Cribl Stream pipelines

Configured routing rules

Parsed log data

Transformed security data

Filtered data

Enriched data

Normalized security telemetry

Reduced or optimized log volume

Built integrations between security-data sources and SIEM platforms

Troubleshot Cribl pipeline failures or data-flow issues

Supported Cribl in a production enterprise environment

Candidates should be able to explain their Cribl architecture data sources destinations transformations routing logic and SIEM integrations in detail.

Avoid candidates whose backgrounds are primarily focused on:

General cybersecurity with no Cribl experience

SIEM administration with no Cribl experience

Splunk administration without Cribl pipeline engineering

SOC Analyst work without security-engineering responsibilities

Security architecture without hands-on implementation

GRC / governance / risk / compliance

IAM-only roles

Network-security roles without security-data pipeline experience

DevOps roles without cybersecurity engineering

Observability roles without enterprise security-data responsibilities

Candidates who list Cribl only in a skills section

Candidates who have only been exposed to Cribl but have not built or supported pipelines

Candidates without meaningful Python or Bash scripting experience

Candidates without enterprise security-tool experience

Candidates without Linux and Windows experience

Candidates previously submitted to Solicitation 11439

Required Candidate Information

Before submission collect and confirm:

Work authorization

Current and future sponsorship requirements

Ability to work directly on CornerStones W-2 when required

Full legal first name

Full legal middle name when applicable

Full legal last name

Personal phone number

Personal email address

Current resident city and state

Ability to work remotely within the United States

Ability to work 40 hours per week

Rate expectations and acceptance

Start availability for October 26 2026

Virtual interview availability and commitment

Ability to attend an in-person final interview if required

Willingness to occasionally travel to Columbia South Carolina if requested

Understanding that any onsite travel expenses are the resources responsibility

No conflicting Right to Represent with another vendor

Confirmation candidate was not previously submitted to Solicitation 11439

Education or qualifying equivalent experience

Must also confirm that the candidate has:

Hands-on Cribl experience

Cribl data modeling experience

Cribl log-pipeline design experience

Cribl implementation experience

Enterprise SIEM experience

Enterprise security architecture or engineering experience

XDR experience when applicable

Vulnerability-management experience when applicable

DLP experience when applicable

Endpoint-security experience

Python scripting experience

Bash scripting experience

Linux experience

Windows experience

System-hardening/security-configuration experience

Networking knowledge

Security-protocol knowledge

Secure-system-design knowledge

Threat-detection experience

Defensive-security experience

At least 5 years supporting large IT environments and/or enterprise system deployments

Preferred experience should also be confirmed when applicable:

Hands-on SIEM administration

SIEM analysis

SIEM reporting

Linux-based security-sensor deployment

NIST CSF

CJIS

IRS 1075

CMS MARS-E

CISSP

Security


Required Skills:

Cribl data modeling experienceCribl log-pipeline designCribl implementationEnterprise SIEMXDR experienceDLP experienceSIEM analysisPython ScriptingBash ScriptingLinux-based security-sensor deploymentNIST CSFCJISSplunkIBM QRadarElastic / ElasticsearchThreat-detection experienceDefensive-security experienceMicrosoft SentinelNIST Cybersecurity Framework / NIST CSF