Join Starr, a global leader in commercial insurance with over a century of expertise. We empower our employees to innovate, make impactful decisions, and build lasting client relationships worldwide. At Starr, you'll work in an entrepreneurial culture alongside accessible leaders, leveraging our financial strength and vast industry experience to deliver solutions for our clients, no matter how complex. Grow your career with a rapidly growing company that invests in its people and their ability to drive real progress.
Security Observability Engineer
Job Overview
We are seeking an experienced Security Observability Engineer to lead the migration, optimization, and secure operation of our log ingestion and observability pipelines. The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high availability for log infrastructure.
Key Responsibilities
pipelines, ensuring load-balanced, fault-tolerant delivery and processing of security and IT logs.
implementation, and operation of load balancing solutions (e.g., Cribl worker groups, external load balancers, or syslog load distribution) for high ingest volumes.
authentication, proxies, etc.)-covering parsing, ltering, and data reduction techniques to minimize Splunk ingest/storage costs without sacricing security coverage.
transformations, eld normalization, masking, and enrichment for security analytics.
Splunk indexers to prevent bottlenecks, data loss, or single points of failure. • Security Event Visibility and SOC Enablement
reach the SIEM eRiciently and reliably, and logs are tuned for actionable detection. • Actively monitor, test, and remediate pipeline balancing and ingestion health to
maximize uptime and forensic visibility.
compliance visibility.
retention, and integrity-ensuring pipeline architecture meets audit, legal, and privacy requirements.
loss/drop rates across the load-balanced infrastructure.
balancing strategies, and operational procedures.
Required Skills & Qualications
heads, clustering, forwarders, CIM, performance/load optimization).
load-balanced pipelines.
balancing strategies (syslog balancers, DNS round-robin, Cribl worker groups, etc.), and high-availability logging environments.
cloud, EDR/XDR, IAM, authentication, and networking) for best possible coverage and SOC/IR support.
SIEM optimization experience.
and validation.
pipeline and SIEM health.
Preferred Qualications
deployments (worker groups, clustered indexers, resilient data forwarders, etc.). • Splunk ES or Cribl certications.
Key Success Metrics
optimization.
operational/storage cost.
overloads-pipeline health and reliability metrics maintained above SLA. • Well-documented, adaptable pipeline and load balancing architecture.
The estimated salary range for this position is 90k-120k
Starr is an equal opportunity employer, which means we'll consider all suitably qualified applicants regardless of gender identity or expression, ethnic origin, nationality, religion or beliefs, age, sexual orientation, disability status or any other protected characteristic. We recruit and develop our people based on merit and we're committed to creating an inclusive environment for all employees. We offer first class training and development opportunities to all employees. Our aim is to grow our own talent and bring out the best in people.