598,796open jobs
30,416companies
86,197added this week
Browse all
Salary
$68k – $144k per year (Estimated)
Location
Remote/Hybrid (Kilkenny, Ireland)
Seniority
Architect · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
State Street is an American financial institution founded in Boston in 1792 and one of the oldest banks in the United States, though its modern business bears little resemblance to retail banking. It is one of the three dominant global custodians, holding trillions of dollars of assets in safekeeping for institutional investors and providing the fund accounting, administration and settlement infrastructure that asset managers depend on. Its investment arm State Street Global Advisors created the first American exchange traded fund with the SPDR S&P 500 Trust and remains one of the largest index managers in the world.

Who we are looking for

We are looking for aSIEM Data Engineerreporting directly to theCyber Data Engineering Manager. You will support the onboarding, transformation, routing, validation, and operational support of cybersecurity telemetry and enterprise log data used for security monitoring, analytics, reporting, incident response, and cyber data science use cases.

This role is focused on understanding diverse enterprise data sources,buildingandmaintainingsecurity telemetry pipelines, validating data quality, and ensuring reliable delivery of high-quality data into cyber data platforms such as Splunk, Databricks, and other SIEM or cyber analytics platforms. You will work closely with cybersecurity, infrastructure, cloud, application, anddata engineering teams to ensure security telemetry isaccurate, searchable, complete, and fit for purpose.

Why This Role Is Important to Us

The team you will be joining is part ofCyber Data & Analytics, a function that is vital to the company as it enables cybersecurity teams to make faster, data-driven decisions and strengthen the firm’s ability to detect, investigate, and respond to evolving cyber threats.

High-quality cybersecurity data is foundational to effective threat detection, incident response, risk reporting, observability, automation, analytics, and compliance. This role helps ensure that enterprise security telemetry is properly onboarded,validated, enriched, routed,monitored, and continuously available to support critical cyber defense capabilities.

What you will be responsible for

As SIEM Data Engineer you will:

  • Support onboarding of security telemetry from applications, infrastructure, endpoints, identity platforms, network devices, cloud services, SaaS tools, databases, and security products.

  • Analyze source log formats and define ingestion requirements, expected fields, metadata, routing needs, and downstream SIEM/analytics use cases.

  • Configure telemetry pipelines for parsing, filtering, masking, enrichment, normalization, event breaking, metadata tagging, and destination routing.

  • Route security telemetry toSplunk, Databricks, and other SIEM or cyber analytics platforms.

  • Support validation and delivery of security telemetry into Databricks across raw, enriched, and curated data layers.

  • Support ingestion patterns such as syslog, HEC, REST APIs, cloud storage, streaming services, forwarders, and agent-based integrations.

  • Validate data quality in Splunk and Databricks for freshness, completeness, timestamp accuracy, field availability, schema consistency, source attribution, and routing accuracy.

  • Troubleshoot ingestion and data flow issues across sources, collectors, pipelines, SIEM platforms, Databricks tables, APIs, cloud storage, and streaming platforms.

  • Providesecond-line-of-defense supportfor operational issues related to data engineering jobs, pipelines, ingestion failures, and issues leading to loss of data delivery to cyber data platforms.

  • Collaborate with Detection Engineering, Security Operations, Cyber Data Science, Observability, Cloud, Infrastructure, Application, and Platform teams to ensure telemetry supports security use cases.

  • Assistwith source type assignment, index routing, taxonomy tagging, metadata enrichment, CIM alignment, schema mapping, and data validation.

  • Monitor pipeline health, dropped events, destination failures, ingestion latency, queue growth, and data delivery issues.

  • Document onboarding patterns, field mappings, transformation logic, routing decisions, data flow diagrams, runbooks, troubleshooting procedures, and operational handoffs.

  • Participate in production support, change management, incident response, root cause analysis, and continuous improvement activities

  • Second-line-of-defense support for operational issues related to data engineering (jobs/pipelines) and issues leading to loss of data delivery to Cyber data platforms

What we value

These skills will help you succeed in this role

  • Strong understanding of SIEM data onboarding, log ingestion, data routing, parsing, enrichment, validation, and troubleshooting.

  • Hands-on experience withSplunkor similar SIEM/log analytics platforms.

  • Hands-on experience or working knowledge ofCribl Streamor similar data pipeline technologies for routing, filtering, parsing, enrichment, transformation, and destination delivery.

  • Ability to understand and onboard telemetry from diverse enterprise data sources across cloud, endpoint, identity, network, application, infrastructure, database, SaaS, and security platforms.

  • Familiarity with common log formats such asJSON, XML, CSV, key-value, syslog, Windows Event Logs, cloud audit logs, API responses, and application logs.

  • Working knowledge of Databricks or similar analytics/lakehouseplatforms is preferred.

  • Familiarity with Databricks data layers and data engineering concepts, including raw data ingestion, enrichment, curated tables, SQL-based validation, and analytics-ready datasets.

  • Ability to useSPL, SQL, Spark SQL, Python, Shell, or PowerShellfor data validation, querying, troubleshooting, and automation.

  • Understandingdata quality concepts, including log fidelity, event completeness, timestamp accuracy, field consistency, duplicate detection, routing validation, and data delivery monitoring.

  • Strong documentation, communication, collaboration, prioritization, and problem-solving skills.

Education & Preferred Qualifications

  • Master's or bachelor'sdegree in computer science, Cybersecurity, Information Technology, Engineering, Data Engineering, Data Analytics, Information Systems, or a related technical field; equivalent work experience may also be considered

  • 5+ years of experience in SIEM engineering, security data engineering, cybersecurity platform operations, or log analytics, with hands-on experience using Splunk or similar SIEM/log analytics platforms.

  • 2+ years of experience with Cribl Stream or similar data pipeline technologies such as Fluent Bit/Fluentd, Vector, Kafka,Syslog, HEC, REST APIs, or cloud-native ingestion services.

  • 2+ years of experience with Databricks, data lakehouseplatforms, large-scale analytics platforms, or security data repositories for telemetry validation, analytics, and data engineering use cases.

  • Experience onboarding,validating, and troubleshooting security telemetry from diverse enterprise sources to support threat detection, observability, incident response, reporting, and cyber analytics use cases.

  • Experience querying and validating data usingSPL, SQL, Spark SQL, Python, or similar languages.

  • Experience analyzing logs from cloud, endpoint, network, identity, infrastructure, application, database, SaaS, and security tools.

  • Experience with production support, issue troubleshooting, ticket documentation, root cause analysis, operational handoffs, and continuous service improvement.

  • Relevant certifications are preferred, includingCribl certificationssuch asCribl Certified Observability Engineer,Splunk certificationssuch asSplunk Certified Admin,Splunk Certified Architect, orSplunk Certified Consultant, or equivalent hands-on platform experience.

  • Cloud, infrastructure, data engineering, or cybersecurity certifications are a plus.

Work Requirement

  • This role may follow a hybrid work model, with in-office presence requiredbased on team, business, and location expectations.

  • Standard working hours are 8:00 AM to 5:00 PM local time for the employee’s designated work location. Flexibility may berequiredfor occasional operational support, release of activities, incident resolution, escalation support, or datadelivery ofrecovery efforts.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
598,796 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Kilkenny
$30k – $62k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
Python
Java
SQL
Scala
Databases
ClickHouse
Apache Iceberg
Presto
Apache Kafka
Trino
AI/ML
Copilot
Cursor
Spark
Airflow
Flink
OpenAI Codex
Apply
$168k – $282k per year • Equity • Remote • Full-Time • 7+ years exp • Bachelor's Degree • Denver • Austin • Boulder • Chicago
Python
JavaScript
C++
AI/ML
AI Agents
DevOps
Splunk
GCP
AWS
Apply
$251k – $417k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • San Jose
Python
Go
Java
C++
DevOps
Splunk
Kubernetes
Platform Engineering
Apply
Firmware Engineer 5 hours ago
Remote/Hybrid • 3+ years exp • Bachelor's Degree
Python
SQL
C++
DevOps
Git
GitHub
Management
Agile
Scrum
Apply
$168k – $245k per year • Equity • Remote/Hybrid • Full-Time • 3+ years exp • San Jose • Reston
Python
DevOps
Terraform
Ansible
Helm
GitOps
AWS
Kubernetes
Amazon EKS
Amazon S3
Apply
$170k – $283k per year • In office • Full-Time • Bachelor's Degree • Princeton
Apply
$130k – $213k per year • Remote/Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • Princeton
Java
SQL
Scala
Databases
Snowflake
Databricks
Oracle
Teradata
Azure SQL Database
DevOps
Azure DevOps
Azure
Docker
Kubernetes
Analytics
ETL/ELT
Azure Data Factory
Dimensional Modeling
Management
Agile
Apply
$120k – $203k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Princeton • Austin
AI/ML
RAG
LLM Guardrails
DevOps
CI/CD
Incident Management
Cybersecurity
Threat Modeling
Apply
$87k – $184k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Quincy
AI/ML
RAG
LLM Guardrails
DevOps
CI/CD
Incident Management
Cybersecurity
Threat Modeling
Apply
$90k – $158k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Quincy
Cybersecurity
ISO 27001
Apply
$68k – $144k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Kilkenny
Python
SQL
PowerShell
Python
pySpark
Databases
Databricks
Apache Kafka
AI/ML
Spark
DevOps
Rest API
Splunk
Fluent Bit
Fluentd
CI/CD
Platform Engineering
Vector
Incident Management
Amazon ECS
Apply
$74k – $157k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Kilkenny
Python
SQL
Databases
Databricks
Analytics
Power BI
ETL/ELT
Management
Agile
Scrum
Apply
$51k – $138k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Kilkenny
Python
SQL
Databases
Snowflake
Databricks
Delta Lake
Apache Kafka
AI/ML
LangGraph
AutoGen
LangChain
Spark
Prompt Engineering
AI Agents
Semantic Kernel
CrewAI
RAG
Semantic Search
LLMOps
Human-in-the-Loop
Semantic Search
LLM Guardrails
Agentic Workflows
Multi-Agent Systems
DevOps
Vector
Apply
$60k – $146k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Kilkenny
Python
JavaScript
TypeScript
Node JS
Python
Flask
FastAPI
pySpark
Databases
Amazon Aurora
AI/ML
Spark
NLP
Frontend
GraphQL
React.js
DevOps
Azure
CI/CD
AWS
Docker
Kubernetes
AWS Lambda
Amazon EC2
Amazon S3
IAM
Management
Agile
Scrum
Apply
$53k – $143k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Kilkenny
Python
SQL
Databases
Snowflake
Databricks
Delta Lake
Apache Kafka
AI/ML
LangGraph
AutoGen
LangChain
Spark
Prompt Engineering
AI Agents
Semantic Kernel
CrewAI
RAG
Semantic Search
LLMOps
Human-in-the-Loop
Semantic Search
LLM Guardrails
Agentic Workflows
Multi-Agent Systems
DevOps
Vector
Apply
See all jobs
This is one of many
598,796 more open roles from verified company boards, updated every day.