Security Dashboard Engineer (m/f) - Remote
Security Dashboard Engineer (m/f)
Start: ASAP
Duration: 6 months
Location: remote
Tasks:
- Lead the design, architecture, and delivery of security dashboards across Raven's multi-cloud platform (AWS, Azure, GCP)
- Own and evolve dashboard pages covering: network observability, flow logs, WAF/ALB analysis, HANA audit events, cloud compliance, system security posture, vulnerability management, and application-layer threat detection
- Write and optimize complex Databricks SQL queries against Delta Lake/Unity Catalog to power Real Time and historical security views
- Lead dashboard development in Plotly Dash (Python) and Grafana Enterprise and drive the transition to new visualization capabilities where needed
- Contribute to and guide development in the React 18/TypeScript ECS Security Portal Front End (SAP UI5, Redux Toolkit, Tailwind CSS)
- Define and evolve the DynamoDB-backed dashboard schema and widget framework in the BFF (Go) layer
- Engage directly with enterprise customers to understand their security operations, translate requirements into dashboard specifications, and deliver tailored solutions
- Drive SIEM integration patterns - ensuring Raven security data flows effectively into customer SOC tooling (Splunk, Microsoft Sentinel, Chronicle, QRadar)
- Define best practices for security data visualization, dashboard performance, and observability across the platform
Skills:
- Proven track record of leading security dashboarding or security analytics initiatives in a production environment
- Experience acting as a technical lead - setting direction, mentoring engineers, and making architectural decisions
- Expert-level experience with Plotly Dash or equivalent Python-based visualization frameworks in production environments
- Expert-level Grafana Enterprise - dashboard architecture, advanced data source configuration, alerting pipelines, and Helm-based Kubernetes deployment
- Expert understanding of security telemetry: network flow logs, WAF/ALB logs, HANA audit events, CSPM findings, vulnerability scan data, identity audit trails, cloud security alerts
- Proven experience building dashboards or analytics platforms for SOC, CSPM, CNAPP, SIEM, SOAR, EDR, or vulnerability management use cases
- Strong understanding of intrusion detection, threat detection logic, and investigation workflows
- Experience integrating with SIEM platforms - Splunk, Microsoft Sentinel, Chronicle, QRadar, or similar - at an engineering level
- Expert-level Databricks - SQL, Delta Lake, Unity Catalog, Lakeview, notebook-based data pipelines, performance optimization
- Python - production-grade Back End services, Dash applications, data pipelines, Redis integration
- Golang - ability to read, extend, and contribute to the Raven API and BFF services
- React 18 + TypeScript - production experience with component architecture, Redux state management, and modern testing (Vitest, Playwright)