Jobs and Careers
SA

Senior Data Platform SIEM Engineer

SAP
Newtown Square, PA, US, 19073, United Statesfull_timeVerifiedPosted 2 Mar 2026
💰 $222,700/yr($131,000/yr$222,700/yr)

About the role

We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed. 

 

Job Description:

At SAP, we are seeking a Senior Data Platform SIEM Engineer to own and evolve our SIEM platforms and to design secure Model Context Protocol (MCP) integrations that let SOC-facing AI assistants safely leverage SIEM context and actions. You will engineer high-quality telemetry pipelines with Cribl, build and maintain infrastructure as code with robust CI/CD, and implement MCP servers/tools/resources that expose controlled SIEM capabilities to LLM clients without compromising security, privacy, or compliance.

 

What you’ll build:

  • SIEM Platform
    • Splunk Enterprise/ES administration: search head, indexer clustering, deployment server, cluster manager, HEC, UF/HF, CIM mapping, datamodel acceleration, ES notable events, risk-based alerting, performance tuning, licensing, and upgrades.
    • Microsoft Sentinel administration: workspace design, data connectors, ASIM/entity mapping, analytics rules, hunting queries, automation (Logic Apps/playbooks), workbooks, watchlists, health and cost/retention management.
  • Telemetry ingestion and normalization
    • Standardize and normalize telemetry across Splunk CIM and Sentinel ASIM for dependable detection and investigation.
    • Integrate diverse sources: Windows event logs/Sysmon, Linux auditd, M365/Entra ID, Defender suite, network/firewall/proxy, EDR, SaaS apps, and cloud audit logs (Azure/AWS/GCP/Alibaba/IBM/Kubernetes).
  • Cribl Stream/Edge engineering
    • Design and maintain Cribl packs and pipelines to parse, enrich, redact, normalize, and route telemetry to Splunk/Sentinel, Data Lake and archival storage (S3/Blob).
    • Optimize ingest and cost with deduplication, sampling, suppression, field pruning, dynamic routing/fan-out; operate worker groups at scale, HA, Replay, and observability dashboards.
  • MCP (Model Context Protocol) integration
    • Design and implement MCP servers with tools/resources that safely wrap Splunk and Sentinel APIs for read-mostly use cases (e.g., search, incident lookup, notable event triage, dashboard/resource retrieval) and tightly controlled actions (e.g., case updates, watchlist changes).
    • Enforce strict guardrails: RBAC and entitlements, schema-validated inputs, allow-listed SPL/KQL macros, scoped queries, rate limiting/throttling, output sanitization/PII redaction, structured responses, and detailed audit trails.
    • Integrate MCP with SOC co-pilots/chatops to enable retrieval-augmented workflows (RAG) using curated detection documentation, playbooks, and MITRE mappings; ensure ephemeral credentials, JIT access, secrets management (Key Vault/Vault), and full observability of MCP usage.
    • Partner with security architecture and privacy teams to align MCP capabilities with policy, regulatory requirements, and safe model interaction patterns.
  • CI/CD and IaC
    • Maintain version-controlled repositories for SPL/KQL, Splunk apps/TAs, Sentinel analytics/playbooks/workbooks, and MCP server code.
    • Automate validation and deployment via GitHub Actions/Jenkins; use Splunk AppInspect and content linters; implement environment promotion and rollback.
    • Use Infrastructure-as-Code (Terraform) for Sentinel resources/connectors/analytics/Logic Apps; manage Splunk configuration as code for reproducible deployments.
  • Reliability, observability, and cost management
    • Define SLOs/SLAs for ingestion timeliness, data quality, SIEM uptime, and MCP availability; monitor via Splunk Monitoring Console, Sentinel health, Cribl observability, and MCP telemetry.
    • Optimize platform and ingestion cost (Splunk GB/day; Sentinel ingestion/retention/Content Hub) via pipeline tuning, tiering, and storage strategies; forecast capacity and manage upgrades, scaling, DR.
  • Security operations enablement

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SAP

View company profile →