About the role
Senior Security Engineer — Security Data Pipelines & Zero Trust Access
About the Role:
We're looking for a Senior Security Engineer to own the design, operation, and scaling of the security data pipeline platform that feeds our SIEM, and to drive automation for our Zero Trust access platform. This is a hands-on engineering role with real ownership: you'll take ambiguous problems ("data delivery is lagging," "this team needs just-in-time access to a new environment") from symptom to root cause to a durable, well-designed solution.
You'll join a Security Engineering & Architecture team responsible for the platforms that power detection, response, and secure access across the enterprise.
What You'll Do:
Own the observability/telemetry pipeline platform (primary focus)
- Serve as the primary administrator and engineer for Cribl Stream: building routes, pipelines, and packs; managing sources and destinations; and shaping data in flight (parsing, enrichment, field extraction, reduction, transformation) before it lands in Splunk and other destinations.
- Design and operate cloud-native data collection across AWS, Azure, and GCP — working with services like SQS/SNS, S3 event notifications, Azure Event Hubs, and GCP Pub/Sub to reliably ingest security telemetry at scale.
- Engineer for reliability and scale: tune persistent queues and backpressure behavior, troubleshoot data delivery and throughput issues, capacity-plan worker infrastructure, implement autoscaling, and design load distribution (e.g., DNS-based or load-balancer-based) so the platform grows gracefully with ingest volume.
- Manage deployments and lifecycle of pipeline infrastructure — upgrades, configuration management, and monitoring of distributed worker fleets.
- Help lead our adoption of Splunk Edge Processor as a complementary data processing tier, building SPL2 pipelines and defining where each tool fits in the overall architecture.
Support and automate our Zero Trust access platform
- Administer a Zero Trust Network Access (ZTNA) / software-defined perimeter platform: handle data access requests, adjust entitlements and policies, and troubleshoot user access issues.
- Build automation (primarily Python) against the platform's APIs to enable just-in-time access — provisioning entitlements automatically from approved request workflows so users get exactly the access they need, only when approved, and lose it when it expires.
- Apply strong networking fundamentals daily: subnetting, IP address planning, routing, DNS, ports/protocols, and TLS.
Engineer, don't just operate
- Take problems from symptom to root cause to redesigned solution.
- Write scripts and tooling to eliminate repetitive work.
- Document architectures and decisions so others can build on your work.
- Partner with SIEM engineers, detection teams, and infrastructure teams to keep security data complete, timely, and cost-efficient.
Nice to Have:
- Cribl certifications (CCOE/Admin) or deep production Cribl Stream experience with packs and distributed worker groups.
- Splunk Edge Processor or SPL2 experience.
- Direct Appgate SDP experience, especially API-driven policy/entitlement automation or ITSM-integrated just-in-time access workflows.
- Infrastructure-as-code and deployment tooling (Terraform, Ansible, CI/CD pipelines, containers/Kubernetes).
- Experience with SIEM cost optimization and data reduction strategies.
- Experience operating security tooling in a regulated enterprise environment.
Who You Are:
- You treat "the data stopped flowing" as an engineering problem, not a ticket to escalate.
- You're comfortable being the subject-matter expert — the person others come to when the platform misbehaves.
- You automate yourself out of repetitive work instinctively.
- You can explain a complex architecture to a security analyst, a network engineer, and a director — and adjust the depth for each.
Other Responsibilities:
- Represents FINRA at speaking engagements with various internal and external constituencies
- Leads multi-level initiatives across Regulatory Operations
- Provides subject mat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s