SIEM Data Onboarding Engineer – Splunk

Il y a 1 jour

Schaarbeek, Brussel-Hoofdstad, Belgique Pauwels Consulting Temps plein 70 000 € - 100 000 € Contrat

Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.

  • Lead the onboarding of new log and telemetry sources into the centralized security platform.
  • Design and implement robust data ingestion pipelines and collection mechanisms.
  • Configure and troubleshoot data normalization using the Splunk Common Information Model.
  • Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
  • Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
  • Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
  • Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
  • Hands-on experience with Splunk CIM, data normalization, and field extractions.
  • Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
  • Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
  • Experience in scripting or automation using Python or PowerShell.
  • Strong understanding of SIEM concepts, log management, and event correlation principles.
  • Proactive and analytical mindset with strong stakeholder management skills.
  • You are fluent in English.

Nice to Haves

  • Hands-on experience with Cribl Stream for telemetry routing and transformation.
  • Understanding of SOC operations and detection engineering.
  • Experience working in large-scale enterprise environments.
  • Knowledge of cloud-native logging and monitoring services.
  • Active knowledge of Dutch and/or French.
  • Start date: ASAP
  • Duration: 6 months
  • Work regime: Full-time
  • Location: Brussels
  • Working model: Hybrid
  • Contract: open to both permanent employees and freelancers