Data Pipeline & Platform Engineer, Observability & Security (Ciudad de México)

Data Pipeline & Platform Engineer, Observability & Security (Ciudad de México)

04 ago
|
Qualcomm
|
Ciudad de México

04 ago

Qualcomm

Ciudad de México

**Company**:Qualcomm Intl Inc., Mexico Branch Office
**Job Area**:Information Technology Group, Information Technology Group > IT Engineering
**General Summary**:
General Summary
This role joins the Qualcomm IT Operations Management and Analytics (ITOMA) team, responsible for managing the general Splunk and Cribl infrastructure across the enterprise.
You will serve as a Splunk platform engineer, supporting the day-to-day administration, health, performance, and upgrade lifecycle of a large-scale, distributed Splunk environment — including search head clusters, indexer clusters, deployment servers, and heavy/universal forwarder fleets. Keeping this infrastructure stable, performant, and current is a foundational expectation of this role.
You will also contribute to a strategic initiative: migrating Qualcomm's security operations (SIEM), while helping maintain and optimize the broader observability data pipeline. Data routing and ingestion will leverage a hybrid approach using Cribl Stream/Edge, Azure Monitor Agent (AMA), and native Sentinel integrations — and you'll support the design, implementation, and operation of these flows at enterprise scale.
Beyond the SIEM migration, you will support data pipelining across the full lifecycle — collection, transformation, routing, filtering, enrichment, and delivery — helping ensure the right data reaches the right platform (Splunk, Sentinel, Datadog, ADX) based on use case, cost, and retention requirements. You will also help evaluate and adopt OpenTelemetry (OTEL) as part of Qualcomm's longer-term strategy to standardize telemetry collection across open, vendor-neutral frameworks.
This is a multi-disciplinary role that works with Security, IT, Engineering, and EDA (Electronic Design Automation)



teams — whose chip design environments generate some of the highest telemetry volumes in the enterprise — to support solutions, onboard data sources, and help enforce data governance standards.
Shape
Principal
**Responsibilities**:
Splunk Administration & Platform Management
Administer and support a large-scale, distributed Splunk environment — including search head clusters (SHC), indexer clusters (IDXC), deployment servers, license masters, monitoring consoles, and heavy/universal forwarder fleets.
Support Splunk version upgrades across multiple tiers (search heads, indexers, forwarders, deployment server) — assisting with compatibility validation, app certification checks, rolling upgrade execution, and post-upgrade testing.
Monitor Splunk cluster health — replication/search factor compliance, bucket integrity, indexer performance, search concurrency, scheduler efficiency, and KV Store stability.
Track Splunk licensing — monitor daily ingestion volumes, identify usage trends, investigate license violations, and help implement controls to prevent overages.
Support capacity planning efforts — helping forecast storage, compute, and indexing needs based on data growth trends and onboarding projections.
Administer index management — index creation, retention policies, data tiering (hot/warm/cold/frozen), and SmartStore configuration where applicable.
Create and manage knowledge objects — field extractions, macros, event types, tags, lookups, data models,



and saved searches — ensuring consistency and reusability across the platform.
Help maintain role-based access controls (RBAC), authentication integrations (SAML/LDAP), and audit compliance for the Splunk environment.
Provide Tier 3 on-call support for Splunk and Cribl platform issues — including incident response for platform outages, ingestion failures, and search performance degradation.
Maintain and update operational runbooks and documentation for Splunk administrative procedures, upgrade playbooks, and recovery processes.
Data Pipeline Engineering & Operations
Build and maintain data pipelines using Cribl Stream/Edge, Splunk forwarders, Azure Monitor Agent (AMA), and observability pipeline frameworks to ingest, transform, filter, and route logs, metrics, and events.
Develop and manage Cribl pipelines — sources, transforms, routes, and destinations — to support scalable log and metric processing across multiple output platforms.
Support data routing strategies across Splunk, Microsoft Sentinel, Datadog, and Azure Data Explorer (ADX), ensuring data delivery aligns with use case, cost, and retention requirements.
Optimize ingestion pipelines to reduce unnecessary data volume through filtering, sampling, aggregation, and transformation — helping drive cost efficiency without compromising observability or security coverage.
Troubleshoot and resolve data ingestion and pipeline issues across distributed systems, including forwarders, collectors, agents, and pipeline infrastructure.
Sentinel Migration & Security Data Flows
Contribute to the SIEM migration, helping build data flows that route security-relevant telemetry to Sentinel via Cribl, AMA, and native connectors.
Work with the Security team to

📌 Data Pipeline & Platform Engineer, Observability & Security (Ciudad de México)
🏢 Qualcomm
📍 Ciudad de México

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: data pipeline & platform engineer, observability & security (ciudad de méxico) / ciudad de méxico

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: data pipeline & platform engineer, observability & security (ciudad de méxico) / ciudad de méxico