Splunk Developer and Platform Owner — Cyber Operations Centre for NATO with security clearance
Il y a 1 jour
Mons, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
This is a hands-on senior engineering post on a cyber defence situational awareness platform, and it has two halves that most roles keep apart. One is development, largely in Splunk: dashboards, data models, searches, automation. The other is operational — supporting the cyber operations centre that uses it every day and translating what they need into something buildable.
You would also be the technical bridge to the development contractor, validating what they deliver before it reaches production. It is a role for someone with ownership rather than a ticket queue.
What you would be doing
Design, develop and maintain dashboards, visualisations and interface components in Splunk.
Build and optimise data models, collections, scheduled searches, macros and related objects.
Implement enhancements and fixes driven by operational priority and user feedback.
Support the integration of new data sources and tools into the platform.
Write automation and supporting scripts in Python, Bash or similar.
Give day-to-day technical and operational support to the operations centre users.
Act as the technical bridge between operational needs and the development contractor.
Gather and prioritise user feedback, and turn it into clear technical requirements.
Validate and test contractor deliverables before production, and support early life support for new releases.
Monitor dashboard performance, data quality and platform health, and drive the improvements.
Contribute to the technical roadmap for the platform.
What you would bring
At least three years hands-on with Splunk — dashboard development, data models, collections, macros, scheduled searches.
Splunk interface development and visualisation practice.
Scripting in Python, Bash or similar, and work with REST APIs and databases.
A solid grasp of vulnerability management, threat intelligence and incident management.
A proven ability to balance operational support against hands-on development.
Communication that works in both directions — technical to operational users, operational to engineers.
English to STANAG 6001 level 3.
Splunk certification, machine learning experience, knowledge of MITRE ATT&CK or vulnerability scoring, and prior work in NATO or another high-security environment are all desirable.