Cyber Security Engineer, VP
Charlotte, NC, US, 28202
SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.
In the Americas, SMBC Group has a presence in the US, Canada, Ireland, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.
This is a hybrid role, requiring the successful candidate to attend our Tralee office.
JOB SUMMARY
PRINCIPAL DUTIES AND RESPONSIBILITIES
- Design, build, and maintain scalable data ingestion pipelines for security log onboarding into SIEM platforms and cloud data services, including Azure Data Explorer and Log Analytics.
- Parse, transform, normalize, enrich, and validate structured and unstructured log data using methods such as JSON parsing, regular expressions, and schema mapping.
- Partner with application, infrastructure, cloud, and security teams to onboard new telemetry sources and verify end-to-end data collection.
- Monitor and validate data quality, including log completeness, integrity, timeliness, and consistency across onboarded sources.
- Troubleshoot ingestion, parsing, transformation, and pipeline issues across cloud and on-premises environments.
- Conduct telemetry gap assessments and recommend new data sources to improve security monitoring and detection coverage.
- Develop and maintain documentation including onboarding procedures, data mappings, source requirements, pipeline configurations, and operational processes.
- Improve automation, ingestion frameworks, and deployment processes to increase scalability, reliability, efficiency, and cost effectiveness.
POSITION SPECIFICATIONS
- 5+ years of experience in cybersecurity, data engineering, security operations, log management, or a related technology discipline.
- Experience onboarding, managing, and validating security log sources within SIEM, security analytics, or cloud data platforms.
- Experience coordinating data onboarding efforts across technical teams, vendors, and business partners.
- Strong knowledge of data parsing, normalization, transformation, and validation techniques.
- Experience working with structured and unstructured data formats, including JSON, XML, CSV, and log-based telemetry.
- Ability to identify and resolve data quality, schema, and pipeline performance issues.
- Familiarity with cloud platforms and related logging, monitoring, and analytics services.
- Understanding of common security telemetry sources, including network, endpoint, identity, application, cloud, and infrastructure logs.
- Knowledge of logging, retention, auditability, and data integrity requirements in regulated environments.
- Experience with scripting or automation using Python, PowerShell, or similar technologies.
- Familiarity with query languages used to investigate, validate, and analyze ingested security data.
- Strong communication, collaboration, and documentation skills.
- Strong attention to detail, sound judgment, and accountability for outcomes.
- Ability to balance operational support, project delivery, and continuous improvement initiatives.
NICE TO HAVE
- Experience with threat detection, incident response, vulnerability management, or cloud security.
- Experience supporting infrastructure-as-code or automated deployment practices.
- Knowledge of cybersecurity data engineering trends, telemetry standards, and security analytics platforms.
- Experience working within a global organization or highly regulated financial services environment.
SMBC’s employees participate in a hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process.
SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.
Nearest Major Market: Charlotte