Job Summary
Job Title: Cribl Engineer – Level 2 (L2)
Role Summary
The Cribl Level 2 Engineer is responsible for operating, supporting, and tuning Cribl environments to ensure reliable log, metric, and event data ingestion and routing. This role focuses on incident resolution, performance optimization, pipeline configuration, and operational support, working under architectural guidance from senior engineers.
Key Responsibilities
Key Responsibilities
- Administer and support Cribl Stream and Edge in production and non-production environments
- Configure and manage pipelines, routes, packs, and destinations
- Troubleshoot data ingestion issues, latency, drops, and parsing errors
- Perform field extraction, filtering, masking, enrichment, and transformations
- Monitor system health, resource usage, and data flow KPIs
- Integrate Cribl with platforms such as:
- Sentinel, ADX and other destinations
- Cloud services (AWS, Azure, GCP)
- Apply log reduction and optimization strategies to control licensing and cost
- Support onboarding of new data sources and applications
- Follow change management, documentation, and incident management processes
- Collaborate with SOC, SRE, DevOps, and platform teams
Skill Requirements
Required Skills & Experience
- 3–6 years of experience in log management, observability, or telemetry engineering
- 2+ years of hands-on experience with Cribl
- Strong understanding of:
- Log formats (JSON, syslog, CSV, XML)
- Regex and Grok
- Linux fundamentals
- Experience with Sentinel or other SIEM platforms
Other Requirements
Desired Skills
- Familiarity with Cribl Edge deployments
- Experience with Git, CI/CD pipelines
- Exposure to security logging and compliance use cases