SonicJobs Logo
Left arrow iconBack to search

Cribl Engineer - Active TS/SCI

ENS Solutions, LLC
Posted 6 hours ago, valid for 19 days
Location

College Park, MD 20742, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • We are looking for a highly experienced Cribl Engineer with over 10 years of experience in logging, observability, or SIEM engineering and 5 years in architecting enterprise-scale log/telemetry pipelines.
  • The role involves leading the architecture and design of Cribl Stream and Edge, building high-throughput pipelines, and optimizing system performance.
  • Candidates must have at least 3 years of hands-on experience with Cribl Stream and Edge in production environments and demonstrate success in operating pipelines at 5–10+ TB/day.
  • The position offers a competitive salary and comprehensive benefits, including free medical/dental/vision coverage, 401k contributions from day one, and professional development assistance.
  • This role requires a TS/SCI clearance and specific DoD certifications, along with strong technical skills in Linux, scripting, and secure data flow design.

Role Overview

We are seeking a highly experienced Cribl Engineer to serve as the principal technical authority for observability pipelines built on Cribl Stream and Cribl Edge. This role is designed for a senior technologist with deep expertise in log/telemetry routing, largescale data engineering, and enterprise-grade observability architectures.

You will shape pipeline strategy, design complex routing and transformation logic, drive platform reliability, mentor senior engineers, and serve as the top technical escalation point for Cribl-related challenges.

What You’ll Do

  • Lead architecture and design for Cribl Stream/Edge across multiple enclaves and data domains.
  • Build high throughput pipelines (multiTB/day) with advanced routing, filtering, enrichment, and replay workflows.
  • Optimize system performance, worker topology, CPU/memory distribution, queues, and transport mechanisms.
  • Engineer secure data flows with masking, tokenization, RBAC, PKI/TLS, and other governance controls.
  • Integrate pipelines with SIEM/analytics ecosystems (Splunk, Elastic, SaaS telemetry platforms, cloud services).
  • Develop HA/DR patterns, reliability frameworks, fleet health metrics, and failure mode response processes.
  • Maintain reusable Cribl packs, shared patterns, runbooks, and operational standards.
  • Serve as the senior escalation point for Cribl issues; interface with vendor engineering as required.
  • Mentor engineers, conduct design reviews, drive engineering excellence, and enforce architectural standards.
  • Support cross functional teams (security, cloud, analytics, infrastructure) on logging and telemetry strategy.

 

  • 10+ years of experience in logging, observability, or SIEM engineering.
  • 5+ years architecting enterprise scale log/telemetry pipelines.
  • 3+ years hands‑on with Cribl Stream and Cribl Edge in production environments.
  • Demonstrated success operating and scaling pipelines at 5–10+ TB/day.
  • Expert-level experience with Splunk forwarding/ingestion, source type management, and indexing practices.
  • Strong Linux fundamentals; scripting expertise (Python/Bash); Git; automation (Ansible/Terraform).
  • Strong understanding of transport protocols (HTTP, TCP, TLS/MTLS), Kafka, S3/object storage.
  • Experience designing secure data flows, including encryption, RBAC, secrets management, and compliance controls.
  • Demonstrated ability to mentor senior engineers and lead technical decision making.
  • Certified Cribl Certified Engineer (CCOE) or equivalent Cribl product expertise.
  • Must possess a TS/SCI; willingness to obtain a CI Poly
  • Must possess the following DoD 8570.01-M certifications or be willing to obtain within 30 days of hire:

o  Information Assurance Technician (IAT) Level II certification (currently Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND).

o  IAT Level III certification requirements (currently CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, or GCIH).

o  Cyber Security Service Provider (CSSP) - Infrastructure Support (IS) certification requirements (currently CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND).

 Preferred Qualifications

  • Expertise creating and maintaining Cribl Packs and reusable pipelines.
  • Experience with cloud telemetry (AWS, Azure, hybrid) and cross‑domain data movement patterns.
  • Familiarity with NIST / CIS control frameworks and secure engineering practices.
  • Experience building observability frameworks for large distributed systems.
  • Vendor engagement experience (Cribl PS, product teams, troubleshooting escalations).

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?

  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS
  • 401k Contribution from Day 1
  • PTO + 11 Paid Federal Holidays
  • Long & Short Term Disability Insurance
  • Group Term Life Insurance
  • Tuition, Certification & Professional Development Assistance
  • Workers’ Compensation
  • Relocation Assistance

Candidate AI Usage Policy

AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.