8+ years of experience in defensive cyber operations, cybersecurity engineering, or security platform architecture
3+ years of experience with SIEM platforms, such as Splunk, Elastic Security, Microsoft Sentinel, or Google Chronicle
3+ years of experience working with stream processing and data brokering tools, such as Apache Kafka, Logstash, Fluentd, or Cribl
Experience designing security data pipeline architectures, including log collection, normalization, enrichment, and routing
Experience with data lake and analytics platforms, such as Databricks, Apace Iceberg, or Snowflake
Experience architecting detection engineering pipelines, threat hunting workflows, and automated response capabilities and integrating EDR or NDR solutions using tools, such as CrowdStrike, Corelight, or Trelix
Experience deploying platforms across cloud, on-premises, and disconnected environments using container orchestration, such as Kubernetes or Red Hat OpenShift, and applying Zero Trust principles and DoD cybersecurity frameworks
Secret clearance
HS diploma or GED
Secret clearance is required