SIEM Data Onboarding Engineer – Splunk & Cribl
Digital
Security
Bachelor
- Location
- Schaerbeek, Brussels-Capital
- Work type
- Consultancy
- Work model
- Fulltime, Hybrid
Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.
Responsibilities
- Lead the onboarding of new log and telemetry sources into the centralized security platform.
- Design and implement robust data ingestion pipelines and collection mechanisms.
- Configure and troubleshoot data normalization using the Splunk Common Information Model.
- Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
- Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
- Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
Requirements
- Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
- Hands-on experience with Splunk CIM, data normalization, and field extractions.
- Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
- Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
- Experience in scripting or automation using Python or PowerShell.
- Strong understanding of SIEM concepts, log management, and event correlation principles.
- Proactive and analytical mindset with strong stakeholder management skills.
- You are fluent in English.
Nice to Haves
- Hands-on experience with Cribl Stream for telemetry routing and transformation.
- Understanding of SOC operations and detection engineering.
- Experience working in large-scale enterprise environments.
- Knowledge of cloud-native logging and monitoring services.
- Active knowledge of Dutch and/or French.
Offer
- Start date: ASAP
- Duration: 6 months
- Work regime: Full-time
- Location: Brussels
- Working model: Hybrid
- Contract: open to both permanent employees and freelancers
# 102924
Chat with Alex
Not sure if this job is right for you? Chat with Alex, our AI career coach, and discover the vacancies that match your profile.
)