Platform Engineer

Lintasarta — Indonesia · Posted ~5 hours ago

Skills

Infrastructure architecture Platform administration SIEM SOAR EDR TIP Data pipelines API integration Automation Cloud infrastructure Security operations APIs Cloud

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A platform engineering role focused on the architecture, deployment, and operation of security infrastructure. You will manage core security platforms, build high-volume log ingestion pipelines, optimize storage and retention, and develop secure API integrations and automation for incident response workflows. The position suits an engineer comfortable operating complex, security-critical infrastructure.

Highlights

Own the architecture and lifecycle of core security platforms while engineering high-volume data pipelines and secure integrations. The role combines infrastructure architecture, automation, storage optimization, and security operations support, with direct impact on automated incident response capabilities.

Description

Roles and Responsibilities: Infrastructure Architecture & Administration Platform Management: Oversee the full lifecycle—architecture, deployment, patching, clustering, and health monitoring—of core SOC platforms (SIEM, SOAR, EDR, TIP).Data Pipeline Engineering: Architect and manage high-volume data ingestion pipelines, ensuring logs from cloud environments, networks, and endpoints are cleanly parsed, normalized, and indexed.Storage & Retention Optimization: Optimize index storage strategies, hot/cold data tier configurations, and long-term compliance log archival to balance operational speed with hardware costs.Automation & Integration (SOAR) API Integration: Connect disparate security platforms, infrastructure systems, and identity providers by writing robust, secure custom API integrations.Playbook Infrastructure: Engineer the backend infrastructure, actions, and custom connectors required for Tier-2 and Incident Response teams to execute automated response playbooks.Agent Deployment: Partner with IT and DevOps teams to manage the automated enterprise-wide deployment, tuning, and health verification of EDR and logging agents.Performance Tuning & Reliability Query Performance Optimization: Audit, test, and tune complex analytical queries (e.g., Splunk SPL, Sentinel KQL) written by detection engineers to prevent system resource exhaustion.High Availability: Implement and test robust backup, disaster recovery, and failover strategies for all critical SOC infrastructure components to guarantee 24/7/365 uptime. Technical Skills & Tools Platform Infrastructure & Engineering SIEM/Data Lake Engineering: Deep architectural knowledge of enterprise platforms, such as Splunk Enterprise (Clustering, Indexer/Search Head architecture), Microsoft Sentinel, Elastic Cloud (ELK), or Cribl Stream.SOAR Infrastructure: Infrastructure-level experience managing orchestration engines like Palo Alto Cortex XSOAR, Splunk SOAR, or Swimlane.DevOps & Infrastructure as Code (IaC): High proficiency deploying infrastructure and configurations using Terraform, Ansible, Docker, or Kubernetes clusters.Linux Administration & Scripting System Administration: Enterprise-level Linux (RHEL, Ubuntu) and Windows Server systems administration, including performance tuning, daemon management, and access controls.Automation Languages: Advanced scripting capabilities in Python, Bash, or Go to build automated utilities, parse custom logs, and manipulate JSON/XML payloads over REST APIs.Cloud Architecture: Deep experience managing native security logging mechanisms across AWS (CloudTrail, VPC Flow), Azure (Event Hubs), and GCP (Pub/Sub). Experience & Qualifications Required Experience Total Systems Engineering Experience: Minimum of 5–7+ years of professional experience in Infrastructure Engineering, DevOps, Cloud Architectures, or Enterprise Systems Administration.Splunk Platform Engineering Footprint: At least 3+ years of dedicated experience architecting, deploying, and maintaining large-scale Splunk environments, with explicit responsibility for managing Splunk Enterprise Security (ES) premium applications.Architecture Scale: Documented history of engineering multi-tier Splunk environments (Clustered Indexers, Search Head Clusters, deployment servers) handling multi-terabyte per day data ingestion pipelines. Splunk ES Specialized Experience Data Model Acceleration: Proven experience configuring, tuning, and troubleshooting Data Model Accelerations (DMA) within Splunk ES to keep search head performance optimized without exhausting storage or CPU infrastructure.CIM Compliance Engineering: Mastery of mapping unstructured log sources (firewall, cloud, identity, endpoint) to the Splunk Common Information Model (CIM) to ensure seamless alerting inside the ES incident review dashboard.RBA Implementation: Direct hands-on experience structuring infrastructure to support Splunk Risk-Based Alerting (RBA) frameworks, including managing risk indexes and object attributions.Data Stream Optimization: Proficiency utilizing Splunk Heavy Forwarders, Splunk Stream, or edge-routing technology (e.g., Cribl Stream, Kafka) to mask, filter, and drop duplicate event streams before they impact Splunk licensing costs. Preferred Professional Certifications: Splunk Enterprise Certified ArchitectSplunk Core Certified ConsultantSplunk Enterprise Security Certified Admin (Highly Preferred)Splunk Cloud Certified AdminCertified Information Systems Security Professional (CISSP)AWS or Microsoft Azure Solutions Architect