Senior Data Platform SIEM Engineer
SAPAbout the role
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
Job Description:
At SAP, we are seeking a Senior Data Platform SIEM Engineer to own and evolve our SIEM platforms and to design secure Model Context Protocol (MCP) integrations that let SOC-facing AI assistants safely leverage SIEM context and actions. You will engineer high-quality telemetry pipelines with Cribl, build and maintain infrastructure as code with robust CI/CD, and implement MCP servers/tools/resources that expose controlled SIEM capabilities to LLM clients without compromising security, privacy, or compliance.
What you’ll build:
- SIEM Platform
- Splunk Enterprise/ES administration: search head, indexer clustering, deployment server, cluster manager, HEC, UF/HF, CIM mapping, datamodel acceleration, ES notable events, risk-based alerting, performance tuning, licensing, and upgrades.
- Microsoft Sentinel administration: workspace design, data connectors, ASIM/entity mapping, analytics rules, hunting queries, automation (Logic Apps/playbooks), workbooks, watchlists, health and cost/retention management.
- Telemetry ingestion and normalization
- Standardize and normalize telemetry across Splunk CIM and Sentinel ASIM for dependable detection and investigation.
- Integrate diverse sources: Windows event logs/Sysmon, Linux auditd, M365/Entra ID, Defender suite, network/firewall/proxy, EDR, SaaS apps, and cloud audit logs (Azure/AWS/GCP/Alibaba/IBM/Kubernetes).
- Cribl Stream/Edge engineering
- Design and maintain Cribl packs and pipelines to parse, enrich, redact, normalize, and route telemetry to Splunk/Sentinel, Data Lake and archival storage (S3/Blob).
- Optimize ingest and cost with deduplication, sampling, suppression, field pruning, dynamic routing/fan-out; operate worker groups at scale, HA, Replay, and observability dashboards.
- MCP (Model Context Protocol) integration
- Design and implement MCP servers with tools/resources that safely wrap Splunk and Sentinel APIs for read-mostly use cases (e.g., search, incident lookup, notable event triage, dashboard/resource retrieval) and tightly controlled actions (e.g., case updates, watchlist changes).
- Enforce strict guardrails: RBAC and entitlements, schema-validated inputs, allow-listed SPL/KQL macros, scoped queries, rate limiting/throttling, output sanitization/PII redaction, structured responses, and detailed audit trails.
- Integrate MCP with SOC co-pilots/chatops to enable retrieval-augmented workflows (RAG) using curated detection documentation, playbooks, and MITRE mappings; ensure ephemeral credentials, JIT access, secrets management (Key Vault/Vault), and full observability of MCP usage.
- Partner with security architecture and privacy teams to align MCP capabilities with policy, regulatory requirements, and safe model interaction patterns.
- CI/CD and IaC
- Maintain version-controlled repositories for SPL/KQL, Splunk apps/TAs, Sentinel analytics/playbooks/workbooks, and MCP server code.
- Automate validation and deployment via GitHub Actions/Jenkins; use Splunk AppInspect and content linters; implement environment promotion and rollback.
- Use Infrastructure-as-Code (Terraform) for Sentinel resources/connectors/analytics/Logic Apps; manage Splunk configuration as code for reproducible deployments.
- Reliability, observability, and cost management
- Define SLOs/SLAs for ingestion timeliness, data quality, SIEM uptime, and MCP availability; monitor via Splunk Monitoring Console, Sentinel health, Cribl observability, and MCP telemetry.
- Optimize platform and ingestion cost (Splunk GB/day; Sentinel ingestion/retention/Content Hub) via pipeline tuning, tiering, and storage strategies; forecast capacity and manage upgrades, scaling, DR.
- Security operations enablement
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s