SIEM Data Onboarding Engineer – Splunk & Cribl
Digital
Security
Bachelor
- Locatie
- Schaarbeek, Brussels Hoofdstedelijk Gewest
- Type werk
- Consultancy
- Werkmodel
- Fulltime, Hybrid
Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.
Verantwoordelijkheden
- Lead the onboarding of new log and telemetry sources into the centralized security platform.
- Design and implement robust data ingestion pipelines and collection mechanisms.
- Configure and troubleshoot data normalization using the Splunk Common Information Model.
- Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
- Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
- Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
Vereisten
- Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
- Hands-on experience with Splunk CIM, data normalization, and field extractions.
- Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
- Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
- Experience in scripting or automation using Python or PowerShell.
- Strong understanding of SIEM concepts, log management, and event correlation principles.
- Proactive and analytical mindset with strong stakeholder management skills.
- You are fluent in English.
Nice to Haves
- Hands-on experience with Cribl Stream for telemetry routing and transformation.
- Understanding of SOC operations and detection engineering.
- Experience working in large-scale enterprise environments.
- Knowledge of cloud-native logging and monitoring services.
- Active knowledge of Dutch and/or French.
Aanbod
- Start date: ASAP
- Duration: 6 months
- Work regime: Full-time
- Location: Brussels
- Working model: Hybrid
- Contract: open to both permanent employees and freelancers
# 102924
Chat met Alex
Twijfel je of deze job bij je past? Praat met Alex, onze AI-carrièrecoach, en ontdek de vacatures die bij jou passen.
)