SIEM Data Onboarding Engineer – Splunk & Cribl
SIEM Data Onboarding Engineer (Splunk & Cribl) voor een telecomklant, hybride in Brussel, fulltime, 6 maanden.
- Locatie
- Schaarbeek, BE
- Werkvorm
- hybride
Eisen
- Fluent in English
- Proactive and analytical mindset with strong stakeholder management skills
- Hands-on experience with Splunk CIM, data normalization, and field extractions
- Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP
- Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL
- Experience in scripting or automation using Python or PowerShell
- Strong understanding of SIEM concepts, log management, and event correlation principles
- Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts
Wensen
- Understanding of SOC operations and detection engineering
- Knowledge of cloud-native logging and monitoring services
- Experience working in large-scale enterprise environments
- Hands-on experience with Cribl Stream for telemetry routing and transformation
- Active knowledge of Dutch and/or French
Volledige omschrijving
Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.
Responsibilities: Lead the onboarding of new log and telemetry sources into the centralized security platform. Design and implement robust data ingestion pipelines and collection mechanisms. Configure and troubleshoot data normalization using the Splunk Common Information Model. Gather technical requirements from stakeholders to align data onboarding with monitoring objectives. Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
Requirements: Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL. Hands-on experience with Splunk CIM, data normalization, and field extractions. Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP. Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts. Experience in scripting or automation using Python or PowerShell.
Strong understanding of SIEM concepts, log management, and event correlation principles. Proactive and analytical mindset with strong stakeholder management skills. You are fluent in English.
Nice to Haves: Hands-on experience with Cribl Stream for telemetry routing and transformation. Understanding of SOC operations and detection engineering. Experience working in large-scale enterprise environments. Knowledge of cloud-native logging and monitoring services. Active knowledge of Dutch and/or French.
Offer: Start date: ASAP.
Duration: 6 months.
Work regime: Full-time.
Location: Brussels.
Working model: Hybrid.
Contract: open to both permanent employees and freelancers.
Je CV en reacties
Voeg een CV toe om de eisen naast jouw ervaring te bekijken.
Je reageert zelf bij de bron. Leg hieronder vast wanneer je je reactie hebt verstuurd.
Bewaar de broker en datum in Mijn reacties.