Engineer - Echo

Target Target · Retail · NCD-0375 Brooklyn Park, MN

This role is for a SIEM Engineer responsible for end-to-end log ingestion into Google SecOps (formerly Chronicle). The engineer will work on onboarding sources, ensuring reliable delivery of data feeds, and building/enhancing ingestion integrations and operational tooling using Python and regular expressions. The role involves troubleshooting production issues, partnering with various security teams, and contributing to monitoring and alerting aligned to platform SLOs/SLAs. The engineer will gain experience with distributed systems fundamentals and resilience patterns, with a focus on improving telemetry quality and reliability.

What you'd actually do

  1. Learn and contribute to end-to-end log ingestion into Google SecOps (formerly Chronicle)—from source onboarding through reliable delivery—so downstream teams can power search, alerting, enrichment, and investigations.
  2. Pair with Threat Management Engineering, Threat Detection & Operations, Cyber Threat Intelligence, and the CSIRT Teams to produce high-quality and backwards compatible changes to large-volume, high-criticality data feeds and SecOps integrations.
  3. Participate in troubleshooting production issues across log pipelines and SIEM integrations (including other SIEM platforms), as part of a shared 24/7 on-call rotation with strong team support and runbooks.
  4. Build and enhance ingestion integrations and operational tooling using Python and practical regular expressions for parsing, validation, and transformations (ECS familiarity is a plus).
  5. Contribute to monitoring and alerting aligned to platform SLOs/SLAs, improving completeness, timeliness, and quality while reducing repeat incidents.

Skills

Required

  • Python
  • regular expressions
  • API integration
  • log/event data manipulation
  • troubleshooting and root-cause analysis
  • distributed systems fundamentals
  • resilience patterns

Nice to have

  • ECS familiarity

What the JD emphasized

  • end-to-end log ingestion
  • high-volume, high-criticality data feeds
  • troubleshooting production issues
  • 24/7 on-call rotation