{"id":1421759,"url":"https://alion.io/job/c-v-starr-co-inc-security-observability-engineer","title":"Security Observability Engineer","company":{"id":1852587,"name":"Starr Companies","domain":"starrcompanies.com","url":"https://alion.io/company/starrcompanies","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":30,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Alpharetta, United States","New York, United States","Atlanta, United States","United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":97000,"max_usd":217000,"period":"year","method":"role_country_seniority_unknown","sample_n":2659},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DNS","optional":false},{"name":"IAM","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-06-23T00:00:00Z","employer_posted_date":"2026-06-23","last_verified_at":"2026-10-01T06:49:21Z","board_verified":true,"closed_at":null,"days_open":101,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":100},"description":"Join Starr, a global leader in commercial insurance with over a century of expertise. We empower our employees to innovate, make impactful decisions, and build lasting client relationships worldwide. At Starr, you'll work in an entrepreneurial culture alongside accessible leaders, leveraging our financial strength and vast industry experience to deliver solutions for our clients, no matter how complex. Grow your career with a rapidly growing company that invests in its people and their ability to drive real progress.\nSecurity Observability Engineer\nJob Overview\nWe are seeking an experienced Security Observability Engineer to lead the migration, optimization, and secure operation of our log ingestion and observability pipelines. The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high availability for log infrastructure.\nKey Responsibilities\nEnd-to-End SIEM Pipeline Management & Optimization\nLead the migration of log sources from Splunk ingestion to Cribl Stream/Edge\npipelines, ensuring load-balanced, fault-tolerant delivery and processing of security and IT logs.\nArchitect and manage scalable, resilient pipelines-including design,\nimplementation, and operation of load balancing solutions (e.g., Cribl worker groups, external load balancers, or syslog load distribution) for high ingest volumes.\nAnalyze, tune and securely onboard all log sources (ﬁrewalls, EDR, cloud,\nauthentication, proxies, etc.)-covering parsing, ﬁltering, and data reduction techniques to minimize Splunk ingest/storage costs without sacriﬁcing security coverage.\nDevelop and maintain Cribl and Splunk conﬁgurations, including advanced\ntransformations, ﬁeld normalization, masking, and enrichment for security analytics.\nEnsure optimal distribution of logging workload across Cribl worker nodes and\nSplunk indexers to prevent bottlenecks, data loss, or single points of failure.\nSecurity Event Visibility and SOC Enablement\nCollaborate with SOC, IR, and threat detection teams to ensure all security logs\nreach the SIEM eRiciently and reliably, and logs are tuned for actionable detection.\nActively monitor, test, and remediate pipeline balancing and ingestion health to\nmaximize uptime and forensic visibility.\nRespond to and resolve SIEM and pipeline issues that impact security, detection, or\ncompliance visibility.\nGovernance, Compliance & Documentation\nApply and document security policies for log routing, load balancing, event\nretention, and integrity-ensuring pipeline architecture meets audit, legal, and privacy requirements.\nTrack and report ingest reduction, Splunk cost savings, pipeline health, and event\nloss/drop rates across the load-balanced infrastructure.\nMaintain clear, up-to-date documentation of log ﬂows, pipeline topology, load\nbalancing strategies, and operational procedures.\nRequired Skills & Qualiﬁ cations\nExtensive hands-on experience with Splunk SIEM engineering (indexers, search\nheads, clustering, forwarders, CIM, performance/load optimization).\n2+ years with Cribl Stream/Edge, including deployment and tuning of distributed,\nload-balanced pipelines.\nDeep understanding of machine data transport (syslog, HEC, TCP, UDP), log\nbalancing strategies (syslog balancers, DNS round-robin, Cribl worker groups, etc.), and high-availability logging environments.\nProven expertise onboarding, parsing, and tuning security log sources (ﬁrewalls,\ncloud, EDR/XDR, IAM, authentication, and networking) for best possible coverage and SOC/IR support.\nAdvanced Splunk SPL, data model, event parsing, and alert tuning skills; practical\nSIEM optimization experience.\nScripting/automation ability (Python, shell/CLI, or similar) for pipeline management\nand validation.\nStrong troubleshooting, monitoring, and operational dashboard skills for both\npipeline and SIEM health.\nPreferred Qualiﬁ cations\nHands-on experience designing and operating clustered/HA Cribl and Splunk\ndeployments (worker groups, clustered indexers, resilient data forwarders, etc.).\nSplunk ES or Cribl certiﬁcations.\nKey Success Metrics\nNo loss of security data or alert coverage during/after pipeline migration and\noptimization.\nDocumented, measurable reductions in Splunk ingest volume and\noperational/storage cost.\nConsistently balanced log throughput and minimal risk of bottlenecks or\noverloads-pipeline health and reliability metrics maintained above SLA.\nWell-documented, adaptable pipeline and load balancing architecture.\nThe estimated salary range for this position is 90k-120k\nStarr is an equal opportunity employer, which means we'll consider all suitably qualified applicants regardless of gender identity or expression, ethnic origin, nationality, religion or beliefs, age, sexual orientation, disability status or any other protected characteristic. We recruit and develop our people based on merit and we're committed to creating an inclusive environment for all employees. We offer first class training and development opportunities to all employees. Our aim is to grow our own talent and bring out the best in people.","description_format":"text","description_chars":5103,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services","Property & Casualty Insurance","Reinsurance"],"lifecycle":[{"event":"open","at":"2026-09-28T22:41:14Z"}],"liveness":{"score":4,"band":"cold","label":"Long shot","p_open":1,"p_active":0.148,"p_room":0.28,"age_days":100,"expected_fill_days":21,"reasons":["conf:9","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/c-v-starr-co-inc-security-observability-engineer","json_url":"https://alion.io/job/c-v-starr-co-inc-security-observability-engineer.json","meta":{"generated_at":"2026-10-02T00:27:32Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":337,"day_limit":5000,"remaining_today":4663,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}