Splunk / Cribl Engineer - Cybersecurity Engineering (Hybrid)
About this opportunity
Company Description
About AbbVie
AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com . Follow @abbvie on LinkedIn, Facebook , Instagram , X and YouTube.
Job Description
As a member of the Cyber Security Engineering (CSE) team within Information Security & Risk Management (ISRM), the Data Engineer focuses on expanding data capabilities. This role is responsible for delivering high-value data management solutions, including data pipelines, models, and SIEM platform optimization, to empower analysts and protect the business.
Responsibilities:
Data Pipeline Development: Design, implement, and enhance robust streaming and batch data pipelines utilizing message brokers to efficiently feed the SIEM and other downstream analytics engines.
Data Transformation & Normalization: Leverage observability pipelines to aggressively route, filter, and normalize/harmonize data, creating structured datasets from unstructured logs prior to SIEM ingestion.
Data Modeling & Architecture: Build scalable data models and enhance standard schemas within data warehousing solutions to deliver reliable, cost-effective, query-optimized storage.
Data Integrity & Lineage: Verify data integrity and translations across distributed systems and message topics while managing end-to-end data lineage.
Development & Integration: Analyze requirements to determine the necessary coding, API integrations, and programming activities to connect disparate security telemetry sources into the SIEM, data warehouses, or other repositories.
Testing & Quality Assurance: Execute testing plans, debug pipeline routing issues, and thoroughly document data flows, routing configurations, and integration protocols.
Data Management Operations: Perform the compilation, cataloging, caching, and rapid retrieval of telemetry within the SIEM and associated data lakes.
Analytics Toolsets: Create, manage, and support advanced analytics and reporting environments operating outside the primary SIEM for long-term security analytics and hunting.
Requirements & Capacity Planning: Define precise data specifications and proactively plan for capacity changes across streaming, routing, indexing, and storage infrastructure.
Governance & Standards: Assist in developing, documenting, and enforcing comprehensive data ingestion standards, parsing policies, and retention procedures across all supported platforms.
Actionable Insights: Analyze diverse data sources across the data stack to uncover trends, improve data quality, and provide actionable recommendations to the security operations team.
Metrics Automation: Develop standards and implement robust automations for metrics aggregation and dissemination, pulling key telemetry from the SIEM and data warehouses.
Qualifications
Required:
Bachelor's Degree with 5 years' experience; or Master's Degree with 4 years' experience
Experienced in writing and optimizing Splunk’s Search Processing Language (SPL)
Proven ability to administer Splunk Enterprise and onboard data sources
Skills in developing data models, dictionaries, and reports within a SIEM platform
Experience building and configuring data pipelines
Experience with regular expressions and parsing unstructured data
Deep understanding of data administration and data standardization policies
Knowledge of database management systems, query languages, table relationships, and views
Experience in validating data sets and calculations
Ability to work both independently without direction and within a group for day-to-day activities
Capable of learning new concepts and processes quickly, and adapting to a constantly changing environment
Experience with CI/CD Pipelines and Git
Experience with database & system integration technologies
Preferred:
Splunk Certified Admin, Power User, or Architect certification
Prior experience working in an Agile team
Familiarity with cybersecurity, privacy principles, cyber threats, and vulnerabilities
Prior experience working with ETL in a SIEM environment (ELK, Splunk, Exabeam, etc.)
Experience working with development tools and scripting languages (Python / PowerShell / Go)
Experience analyzing and pivoting on large sets of data, with the ability to identify patterns, anomalies, and outliers
Cribl Certified User, Admin Stream, or Engineer
Demonstrated experience in log analysis and parsing of unstructured data (ETL)
Amazon Solutions Architect / Azure Data Engineer Associate / Cloud Professional Data Engineer Certification
Additional Information
Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:
The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.
We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.
This job is eligible to participate in our short-term incentive programs.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law.
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.
US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:
https://www.abbvie.com/join-us/reasonable-accommodations.html
Job details
How this role compares
Computed from every other active Information Technology role in our database, not just this employer's listings.
We currently track 1097 comparable Information Technology roles across 55 biopharma companies.
Salary context
142 of 1097 peers report a salary range (USD, annualized)
Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.
Where these roles are based
Top locations among the 1097 comparable roles
+ 23 more countries
Seniority mix
612 of 1097 peers have a known seniority level
Therapeutic area mix
1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden
Similar opportunities
The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.
How we calculate "similar"
No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.
Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.
0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.