Lead and perform configuration and development activities related to XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and storage lifecycle management within the primary security analytics platform
Onboard new client and internal data sources into the Managed Security SIEM environment through a variety of collection and transport methods, including API-based ingestion, syslog, agents, file-based collection, forwarders, cloud-native connectors, and other supported methods
Develop, maintain, and tune parsers, field extractions, transformations, and normalization logic to ensure incoming telemetry is usable, consistent, and aligned to Managed Security standards
Partner with Managed Security analysts, detection engineers, and client technical teams to define log source requirements for visibility, detection content, investigations, and reporting
Establish and maintain data standards for source naming, field usage, tagging, metadata, categorization, and normalization across multiple client environments
Support and optimize ingestion pipelines to ensure reliability, scale, and performance across diverse client log sources and varying data volumes
Perform troubleshooting of data collection, transport, parser, and indexing issues, including validation of connectivity, format, mapping, field extraction, and downstream search usability
Manage data tiering, storage allocation, retention strategies, and index lifecycle practices to ensure telemetry is retained appropriately and efficiently based on operational, contractual, and cost requirements
Perform storage optimization and capacity planning activities within the SIEM platform to ensure ingestion remains within contracted scope while preserving the data needed for security operations and investigations
Analyze data quality and data health across sources, including completeness, timeliness, parsing success, normalization coverage, duplication, and consistency
Identify and implement opportunities to improve data pipeline efficiency, reduce noise, eliminate unnecessary data, and improve search and analytics performance
Partner with SIEM, detection, and SOAR engineering resources to ensure standardized and enriched data supports dashboards, detections, automations, and incident workflows
Build and maintain dashboards, reports, and health checks related to ingestion performance, parser quality, storage consumption, retention compliance, and onboarding progress
Create tooling and scripts in Python or similar languages to automate onboarding checks, parser validation, data quality assessments, and platform administration tasks
Assist with the development of processes and procedures to improve onboarding consistency, parser governance, data quality, and overall Managed Security functions
Participate in client-facing security and technical meetings to support onboarding efforts, explain data requirements, review issues, and coordinate implementation activities