Description
Routes Zscaler, Island, and third-party session telemetry through Cribl into Devo and builds detection content for anomalous third-party access.
Responsibilities
- Build and maintain Cribl Devo security telemetry pipelines.
- Integrate Zscaler, Island, and third-party security/session data.
- Normalize, enrich, filter, and troubleshoot security logs.
- Develop Devo SIEM detection rules, alerts, and dashboards.
- Detect anomalous third-party access, suspicious sessions, and unusual authentication activity.
- Support SOC investigations and improve telemetry coverage.
Required Skills
- Hands-on Cribl and Devo SIEM experience.
- Experience with Zscaler and/or Island telemetry.
- Strong SIEM, log management, and detection engineering knowledge.
- Understanding of IAM, SSO, MFA, OAuth/SAML, and third-party access.
- Experience with APIs, JSON, Syslog, and security data pipelines.
- Scripting experience with Python or PowerShell preferred.