SIEM Data Onboarding Engineer – Splunk
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.
- Lead the onboarding of new log and telemetry sources into the centralized security platform.
- Design and implement robust data ingestion pipelines and collection mechanisms.
- Configure and troubleshoot data normalization using the Splunk Common Information Model.
- Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
- Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
- Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
- Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
- Hands-on experience with Splunk CIM, data normalization, and field extractions.
- Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
- Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
- Experience in scripting or automation using Python or PowerShell.
- Strong understanding of SIEM concepts, log management, and event correlation principles.
- Proactive and analytical mindset with strong stakeholder management skills.
- You are fluent in English.
Nice to Haves
- Hands-on experience with Cribl Stream for telemetry routing and transformation.
- Understanding of SOC operations and detection engineering.
- Experience working in large-scale enterprise environments.
- Knowledge of cloud-native logging and monitoring services.
- Active knowledge of Dutch and/or French.
- Start date: ASAP
- Duration: 6 months
- Work regime: Full-time
- Location: Brussels
- Working model: Hybrid
- Contract: open to both permanent employees and freelancers