SIEM Data Onboarding Engineer – Splunk & Cribl

SIEM Data Onboarding Engineer (Splunk & Cribl) voor een telecomklant, hybride in Brussel, fulltime, 6 maanden.

Locatie
Schaarbeek, BE
Werkvorm
hybride

Geen duidelijke warme-stoelaanwijzingen in de beschikbare beoordeling.

Bekijk en reageer bij Pauwels Consulting (externe link)

Eisen

  • Fluent in English
  • Proactive and analytical mindset with strong stakeholder management skills
  • Hands-on experience with Splunk CIM, data normalization, and field extractions
  • Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP
  • Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL
  • Experience in scripting or automation using Python or PowerShell
  • Strong understanding of SIEM concepts, log management, and event correlation principles
  • Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts

Wensen

  • Understanding of SOC operations and detection engineering
  • Knowledge of cloud-native logging and monitoring services
  • Experience working in large-scale enterprise environments
  • Hands-on experience with Cribl Stream for telemetry routing and transformation
  • Active knowledge of Dutch and/or French
Volledige omschrijving

Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.

Responsibilities: Lead the onboarding of new log and telemetry sources into the centralized security platform. Design and implement robust data ingestion pipelines and collection mechanisms. Configure and troubleshoot data normalization using the Splunk Common Information Model. Gather technical requirements from stakeholders to align data onboarding with monitoring objectives. Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.

Optimize telemetry data flows to improve platform performance and achieve cost efficiency.

Requirements: Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL. Hands-on experience with Splunk CIM, data normalization, and field extractions. Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP. Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts. Experience in scripting or automation using Python or PowerShell.

Strong understanding of SIEM concepts, log management, and event correlation principles. Proactive and analytical mindset with strong stakeholder management skills. You are fluent in English.

Nice to Haves: Hands-on experience with Cribl Stream for telemetry routing and transformation. Understanding of SOC operations and detection engineering. Experience working in large-scale enterprise environments. Knowledge of cloud-native logging and monitoring services. Active knowledge of Dutch and/or French.

Offer: Start date: ASAP.

Duration: 6 months.

Work regime: Full-time.

Location: Brussels.

Working model: Hybrid.

Contract: open to both permanent employees and freelancers.

Je CV en reacties