Cribl data modeling and log-pipeline engineering is the central requirement for this role
Do not move forward with a candidate unless the required hands-on Cribl experience, enterprise security engineering experience, SIEM experience, Python/Bash scripting, operating-system security experience, rate expectations, screening requirements, education/experience requirements, work-location requirements, and required submission documents have been confirmed.
Job Information
-
Working Title: Security Architect Consultant Data Modeling Engineer (Cribl)
-
Category: IT / Cybersecurity
-
Visa: W2 (Independent), Locals
This position is 100% remote
Position Overview
-
The State of South Carolina is seeking an experienced Security Architect Consultant Data Modeling Engineer with deep hands-on experience using Cribl to design, implement, and maintain enterprise security-data pipelines.
-
This is not a general cybersecurity architect or SIEM administrator position.
-
The central requirement is hands-on experience with Cribl data modeling, log-pipeline design, implementation, routing, transformation, and delivery of security telemetry into enterprise SIEM environments.
-
The selected consultant will work alongside full-time security architects and engineers supporting large-scale enterprise cybersecurity initiatives.
-
The role combines Cribl engineering with broader hands-on security engineering across SIEM, XDR, vulnerability management, DLP, endpoint security, Linux security sensors, Windows/Linux security configuration, security integrations, automation, threat detection, and defensive security architecture.
-
Automation is also important. Candidates should demonstrate experience building integrations and security automation using scripting languages such as Python and Bash.
-
The strongest candidates will have substantial experience operating within complex enterprise security environments rather than simply having exposure to Cribl or SIEM technologies.
Scope of Project
The selected consultant will support:
Cribl data modeling
Cribl Stream / log-pipeline architecture
Enterprise log ingestion
Security-data routing
Parsing and transformation of security telemetry
Data normalization and enrichment
SIEM data delivery and integration
SIEM administration, analysis, and reporting
Enterprise security architecture
Security-tool implementation and support
XDR technologies
Vulnerability-management platforms
Data Loss Prevention / DLP
Endpoint security
Linux-based security sensors
Windows and Linux security configuration
Security-system hardening
Cybersecurity automation
Python scripting
Bash scripting
Security integrations
Threat detection
Defensive security strategies
Networking and secure-system design
Security controls and countermeasures
Security-control validation
Incident-detection support
Enterprise cybersecurity engineering
Daily Duties / Responsibilities
The selected candidate will:
Design, build, implement, and maintain Cribl data models and log pipelines
Develop enterprise security-data ingestion and routing workflows
Configure pipelines that deliver security telemetry into enterprise SIEM environments
Perform data parsing, filtering, transformation, enrichment, routing, and normalization
Work directly with enterprise security architects and engineers
Support SIEM administration, analysis, and reporting
Implement and support enterprise security technologies
Support XDR platforms
Support vulnerability-management technologies
Support DLP technologies
Support endpoint-security platforms
Build and deploy Linux-based security sensors
Support Linux and Windows security configuration and hardening
Develop security automation and integrations using Python and Bash
Support enterprise threat-detection capabilities
Assist with defensive-security engineering
Support security-control implementation and validation
Participate in enterprise security architecture discussions
Support incident-detection activities
Troubleshoot complex security-data and integration issues
Support secure networking and system-design initiatives
Participate in the required on-call rotation
Required Qualifications
The candidate must have:
Hands-on Cribl data modeling experience
Cribl log-pipeline design and implementation experience
Strong understanding of enterprise security architecture and engineering principles
Experience implementing and supporting enterprise security tools
Security-tool experience should include exposure to technologies such as:
SIEM
XDR
Vulnerability Management
Data Loss Prevention / DLP
Endpoint Security
The candidate must also have:
Experience developing automation and integrations using Python and/or Bash
Knowledge of cybersecurity best practices
Threat-detection experience
Defensive-security knowledge
Linux operating-system experience
Windows operating-system experience
System-hardening experience
Security-configuration experience
Understanding of networking concepts
Understanding of security protocols
Understanding of secure-system design
5+ years of experience supporting large IT environments and/or enterprise system deployments
All required experience should be clearly and explicitly documented in the resume.
Do not rely solely on a skills section or broad statements such as:
"Cribl"
"SIEM"
"Cybersecurity"
"Security Architecture"
"Python"
The resume should establish what the candidate actually designed, configured, implemented, supported, automated, integrated, or administered.
For Cribl specifically, the resume should demonstrate meaningful hands-on responsibility rather than simple platform exposure.
Required Education
The candidate should have:
Bachelor's degree in an Information Technology-related field
OR
Bachelor's degree in a Security-related field
OR
8+ years of relevant professional experience may be substituted in lieu of the degree requirement
Please confirm the candidate's education and/or qualifying equivalent experience before submission.
Preferred Qualifications
Preferred experience includes:
Hands-on Cribl data modeling experience
Advanced Cribl Stream experience
SIEM administration
SIEM analysis
SIEM reporting
Building and deploying Linux-based security sensors
Enterprise cybersecurity engineering
Security architecture
Security automation
Security-system integration
NIST Cybersecurity Framework / NIST CSF
CJIS
IRS Publication 1075
CMS MARS-E
Preferred certifications include:
CISSP
Security+
The strongest candidates will demonstrate multiple preferred qualifications, but hands-on Cribl remains the most important technical signal.
Additional Skills
The candidate should also demonstrate:
Strong enterprise security-engineering capabilities
Strong troubleshooting and analytical skills
Strong technical communication skills
Ability to work with security architects and engineering teams
Ability to design scalable security-data pipelines
Ability to troubleshoot log-ingestion and routing issues
Ability to automate repetitive security-engineering processes
Ability to understand complex security-data flows
Strong Linux skills
Strong Windows-security knowledge
Strong networking fundamentals
Ability to work independently in a remote environment
Ability to participate in an on-call environment
Target Candidate Profile
Focus on candidates with backgrounds such as:
Cribl Engineer
Cribl Stream Engineer
Security Data Engineer
Security Data Pipeline Engineer
SIEM Engineer
Senior SIEM Engineer
Security Engineer
Senior Security Engineer
Security Architect
Cybersecurity Engineer
Security Platform Engineer
Security Automation Engineer
Logging / Telemetry Engineer
Observability Engineer
Detection Engineer
Security Infrastructure Engineer
The strongest candidates will have:
5+ years of enterprise IT/security experience
Real hands-on Cribl Stream experience
Cribl data modeling experience
Cribl pipeline-design experience
Log-ingestion experience
Log-routing experience
Parsing and transformation experience
Data normalization experience
Security telemetry experience
Enterprise SIEM experience
SIEM administration or engineering experience
Python scripting experience
Bash scripting experience
Linux security experience
Windows security experience
Security automation experience
Security-tool integration experience
XDR experience
Vulnerability-management experience
DLP experience
Endpoint-security experience
Networking/security-protocol knowledge
Threat-detection experience
Defensive-security experience
Experience supporting large enterprise environments
Especially strong profiles may combine Cribl with SIEM platforms such as:
Splunk
Microsoft Sentinel
IBM QRadar
Elastic / Elasticsearch
Other large-scale enterprise SIEM platforms
Cribl Screening Standard
Treat Cribl as a true knockout requirement.
Do not move forward based solely on a candidate mentioning Cribl in a skills section.
During screening, confirm specifically whether the candidate has personally:
Designed Cribl pipelines
Built Cribl Stream pipelines
Configured routing rules
Parsed log data
Transformed security data
Filtered data
Enriched data
Normalized security telemetry
Reduced or optimized log volume
Built integrations between security-data sources and SIEM platforms
Troubleshot Cribl pipeline failures or data-flow issues
Supported Cribl in a production enterprise environment
Candidates should be able to explain their Cribl architecture, data sources, destinations, transformations, routing logic, and SIEM integrations in detail.
Avoid candidates whose backgrounds are primarily focused on:
General cybersecurity with no Cribl experience
SIEM administration with no Cribl experience
Splunk administration without Cribl pipeline engineering
SOC Analyst work without security-engineering responsibilities
Security architecture without hands-on implementation
GRC / governance / risk / compliance
IAM-only roles
Network-security roles without security-data pipeline experience
DevOps roles without cybersecurity engineering
Observability roles without enterprise security-data responsibilities
Candidates who list Cribl only in a skills section
Candidates who have only been exposed to Cribl but have not built or supported pipelines
Candidates without meaningful Python or Bash scripting experience
Candidates without enterprise security-tool experience
Candidates without Linux and Windows experience
Candidates previously submitted to Solicitation 11439
Required Candidate Information
Before submission, collect and confirm:
Work authorization
Current and future sponsorship requirements
Ability to work directly on CornerStone's W-2, when required
Full legal first name
Full legal middle name, when applicable
Full legal last name
Personal phone number
Personal email address
Current resident city and state
Ability to work remotely within the United States
Ability to work 40 hours per week
Rate expectations and acceptance
Start availability for October 26, 2026
Virtual interview availability and commitment
Ability to attend an in-person final interview if required
Willingness to occasionally travel to Columbia, South Carolina if requested
Understanding that any onsite travel expenses are the resource's responsibility
No conflicting Right to Represent with another vendor
Confirmation candidate was not previously submitted to Solicitation 11439
Education or qualifying equivalent experience
Must also confirm that the candidate has:
Hands-on Cribl experience
Cribl data modeling experience
Cribl log-pipeline design experience
Cribl implementation experience
Enterprise SIEM experience
Enterprise security architecture or engineering experience
XDR experience, when applicable
Vulnerability-management experience, when applicable
DLP experience, when applicable
Endpoint-security experience
Python scripting experience
Bash scripting experience
Linux experience
Windows experience
System-hardening/security-configuration experience
Networking knowledge
Security-protocol knowledge
Secure-system-design knowledge
Threat-detection experience
Defensive-security experience
At least 5 years supporting large IT environments and/or enterprise system deployments
Preferred experience should also be confirmed when applicable:
Hands-on SIEM administration
SIEM analysis
SIEM reporting
Linux-based security-sensor deployment
NIST CSF
CJIS
IRS 1075
CMS MARS-E
CISSP
Security+