Charlotte, NC

Salary
$55–$62/hrfrom the description
Posted
Aug 5, 2026
Location
Charlotte, NC
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A W2 contract role embedded in a financial services firm's Cyber Security Operations department, focused on building and maintaining data ingestion pipelines that bring security log sources into SIEM and cloud analytics platforms. The work centers on parsing, normalizing, and validating structured and unstructured log data to support detection, monitoring, and response use cases. Suited to a data engineer with hands-on security telemetry and log management experience.

Mid level · 3+ years · Charlotte-Concord-Gastonia, NC-SC · Contract

Must have (8)
SIEMAzure Data ExplorerLog AnalyticsregexJSONXMLCSVcloud platforms, AWS, GCP or Azure

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 15 people in the Charlotte-Concord-Gastonia, NC-SC area plausibly meet what this posting asks for (database architects). range 3–25

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
SIEM3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
cloud platforms50%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $141,924 (middle half $120,421–$172,379). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 6, 2026. It is a model, not a headcount.

Why we read it this way (8)

Azure Data Explorer and Log Analytics are explicitly named in the responsibilities section as target platforms; they are treated as hard gates given the specificity of the role's day-to-day work.

The posting names no specific SIEM product (e.g. Splunk, Microsoft Sentinel, QRadar) — only the generic category 'SIEM' is required.

Cloud platform experience is required but no specific provider is named beyond Azure services already captured; alternatives reflect the most common peers.

'Data pipeline development' appears only in narrative/context sections and is omitted as a named skill per guidelines — the concrete techniques (regex, JSON, XML, CSV) are captured instead.

The role sits at the intersection of data engineering and cybersecurity; the alternative occupation 15-1212 (Information Security Analysts) is noted because the role supports a security operations mission, but the primary day-to-day work is building and validating data pipelines, pointing to 15-1243.

The posting is W2 contract only; local-to-NC candidates are explicitly required, making this a hybrid (3 days onsite) non-remote engagement.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): data pipeline development.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗