Senior Syslog Engineer
Securonix
Skill Required
Key highlights
- High-volume syslog pipeline design (10K–100K+ EPS)
- securonix.com - Leading SIEM platform company
- Vista Equity Partners backed
- Fortune 100 customers
- Gartner Magic Quadrant Leader (6 times)
- Securonix Unified Defense SIEM - industry's first agentic AI-powered platform with human-in-the-loop
Role overview
Securonix is leading the transformation of cybersecurity by helping organizations stay ahead of modern threats, addressing the gap between available data/tools and the speed, clarity, and confidence security teams need. The company's Unified Defense SIEM platform is powered by agentic AI with a human-in-the-loop philosophy, unifying detection, investigation, and response in a single system with advanced UEBA, native threat intelligence, and real-time analytics. The platform enables investigations to move from days to minutes and response to become consistent and measurable, serving over 1,000 customers worldwide including a meaningful portion of the Fortune 100. Backed by Vista Equity Partners, Securonix operates at global scale with an ecosystem of partners and MSSPs. The company emphasizes teamwork, customer-driven innovation, and operational agility.
Responsibilities
- Design, implement, and optimize syslog-ng configurations for high-volume log ingestion environments
- Develop and maintain complex filtering logic to ensure accurate routing, normalization, and noise reduction of logs
- Analyze and improve log pipeline performance (CPU, memory, latency, throughput)
- Build efficient, scalable, and fault-tolerant syslog architectures
- Optimize buffering, batching, and flow control mechanisms in syslog-ng
- Work closely with SIEM platforms (e.g., Securonix, Splunk, ELK) to ensure seamless ingestion
- Ensure log integrity, reliability, and completeness across the pipeline
- Perform capacity planning and load testing for syslog pipelines
- Create test frameworks to validate syslog filters and configurations
- Document standards, guidelines, and reusable configurations
Requirements
- Deep expertise in syslog-ng (mandatory)
- RFC3164
- RFC5424
- TCP/UDP/TLS behavior
- Expertise in designing syslog filters and routing logic
- Strong experience with log parsing, pattern matching, and regex optimization
- Understanding of backpressure, buffering, and flow control
- Experience handling high EPS (10K–100K+) environments
- Troubleshooting experience with message loss, duplicate events, out-of-order processing, and high CPU/memory usage
- Familiarity with tools: tcpdump, netstat, ss, top, strace
- Splunk / ELK / QRadar
- Knowledge of data enrichment and normalization
Nice to have
- Experience with Kafka-based ingestion pipelines
- Knowledge of distributed systems and streaming architectures
- Experience with cloud environments (AWS)
- Familiarity with security logs (firewalls, IAM, endpoint, network devices)
Additional details
- Performance & Reliability concepts: log-iw-size, log-fifo-size, flush_lines, so_rcvbuf, disk-buffer and memory management
- log parsing: RFC3164, RFC5424, structured vs unstructured logs, Secure syslog (TLS)
- Understanding of log ingestion pipelines (Kafka, Spark, etc.)
- Securonix is recognized as a six-time Leader in the Gartner Magic Quadrant for SIEM and a Customers' Choice on Gartner Peer Insights
- Company featured by leading publications including WIRED, Dark Reading, and Fortune
- Backed by Vista Equity Partners
- Operates at global scale with 1,000+ customers worldwide including Fortune 100
- Ecosystem of partners and managed security service providers
- Equal employment opportunity policy
- Prohibition of unlawful employee harassment based on protected characteristics
- Original posting on Himalayas