Pauwels Consulting Logo
Apply now

SIEM Data Onboarding Engineer – Splunk & Cribl

Digital
Security
Bachelor
Location
Schaerbeek, Brussels-Capital
Work type
Consultancy
Work model
Fulltime, Hybrid

Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.

Responsibilities

  • Lead the onboarding of new log and telemetry sources into the centralized security platform.
  • Design and implement robust data ingestion pipelines and collection mechanisms.
  • Configure and troubleshoot data normalization using the Splunk Common Information Model.
  • Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
  • Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
  • Optimize telemetry data flows to improve platform performance and achieve cost efficiency.

Requirements

  • Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
  • Hands-on experience with Splunk CIM, data normalization, and field extractions.
  • Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
  • Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
  • Experience in scripting or automation using Python or PowerShell.
  • Strong understanding of SIEM concepts, log management, and event correlation principles.
  • Proactive and analytical mindset with strong stakeholder management skills.
  • You are fluent in English.

Nice to Haves

  • Hands-on experience with Cribl Stream for telemetry routing and transformation.
  • Understanding of SOC operations and detection engineering.
  • Experience working in large-scale enterprise environments.
  • Knowledge of cloud-native logging and monitoring services.
  • Active knowledge of Dutch and/or French.

Offer

  • Start date: ASAP
  • Duration: 6 months
  • Work regime: Full-time
  • Location: Brussels
  • Working model: Hybrid
  • Contract: open to both permanent employees and freelancers
# 102924
With a plus sign and country code (e.g. +32 400 00 00 00).
We accept Word and PDF files up to 3 MB.
Candidates must be legally authorised to work in the EU and possess the required language skills for the job location.
Chat with Alex
Not sure if this job is right for you? Chat with Alex, our AI career coach, and discover the vacancies that match your profile.