SIEM Data Onboarding Engineer – Splunk & Cribl

Pauwels Consulting

Schaarbeek

Hybride

EUR 70 000 - 100 000

Plein temps

Il y a 5 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV personnalisé et une lettre de motivation qui correspondent directement à l’offre.

Passez les filtres ATS

Résumé du poste

Pauwels Consulting in Brussels is seeking a security data engineer to help integrate diverse log and telemetry sources into a Splunk-based SIEM. You will design ingestion pipelines and ensure reliable data flows across on-prem and cloud environments.

The role requires hands-on Splunk experience, proficiency with JSON/XML/Syslog, and automation skills in Python or PowerShell. A proactive, stakeholder-facing mindset and fluency in English are essential.

Qualifications

  • Must have hands-on Splunk experience (Enterprise/Cloud) including CIM and data normalization.
  • Experience with Windows, Linux, and cloud logs (Azure/AWS/GCP).
  • Proficient in JSON, XML, Syslog, REST APIs; scripting in Python or PowerShell.
  • Strong SIEM concepts, log management, and data onboarding workflow knowledge.
  • Fluent in English with good stakeholder management skills.

Responsabilités

  • Lead onboarding of new log and telemetry sources into the centralized Splunk-based SIEM.
  • Design and implement robust data ingestion pipelines and collection mechanisms.
  • Configure and troubleshoot data normalization using Splunk CIM.
  • Gather technical requirements from stakeholders to align onboarding with monitoring objectives.
  • Perform data quality assessments and resolve complex ingestion issues.
  • Optimize telemetry data flows to improve performance and cost efficiency.

Connaissances

Splunk Enterprise
Splunk Cloud
Universal Forwarders
Heavy Forwarders
SPL
Splunk CIM
Data normalization
Windows logs
Linux logs
Azure logs
AWS logs
GCP logs
JSON
XML
Syslog
REST APIs
Python
PowerShell
SIEM concepts
Log management
Stakeholder management
English fluency

Outils

Cribl Stream

Description du poste

Our client, a leading player in the telecommunications and digital services sector, is seeking a specialist to strengthen their global security operations. The role focuses on integrating diverse log and telemetry sources into a Splunk-based SIEM platform to enhance detection and monitoring capabilities. The project involves designing efficient ingestion pipelines and optimizing data flows to support complex security use cases.

  • Lead the onboarding of new log and telemetry sources into the centralized security platform.
  • Design and implement robust data ingestion pipelines and collection mechanisms.
  • Configure and troubleshoot data normalization using the Splunk Common Information Model.
  • Gather technical requirements from stakeholders to align data onboarding with monitoring objectives.
  • Perform data quality assessments and resolve complex ingestion issues to ensure log fidelity.
  • Optimize telemetry data flows to improve platform performance and achieve cost efficiency.
  • Proven experience with Splunk Enterprise or Splunk Cloud, including Universal Forwarders, Heavy Forwarders, and SPL.
  • Hands-on experience with Splunk CIM, data normalization, and field extractions.
  • Professional knowledge of security logs from Windows, Linux, and cloud platforms such as Azure, AWS, or GCP.
  • Technical expertise in JSON, XML, Syslog, REST APIs, and event streaming concepts.
  • Experience in scripting or automation using Python or PowerShell.
  • Strong understanding of SIEM concepts, log management, and event correlation principles.
  • Proactive and analytical mindset with strong stakeholder management skills.
  • You are fluent in English.
Nice to Haves
  • Hands-on experience with Cribl Stream for telemetry routing and transformation.
  • Understanding of SOC operations and detection engineering.
  • Experience working in large-scale enterprise environments.
  • Knowledge of cloud-native logging and monitoring services.
  • Active knowledge of Dutch and/or French.
  • Start date: ASAP
  • Duration: 6 months
  • Work regime: Full-time
  • Location: Brussels
  • Working model: Hybrid
  • Contract: open to both permanent employees and freelancers
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Splunk & Cribl SIEM Onboarding Engineer (Hybrid Brussels)
Splunk & Cribl SIEM Onboarding Engineer (Hybrid Brussels)

Pauwels Consulting • Schaarbeek

Hybride
EUR 70 000 - 100 000
SIEM Data Engineer - Brussel-centrum
SIEM Data Engineer - Brussel-centrum

Editx • Brussel

Sur place
EUR 65 000 - 90 000
SIEM Data Onboarding Engineer (Splunk)
SIEM Data Onboarding Engineer (Splunk)

IT-Planet NV • Gent

Sur place
EUR 90 000 - 120 000
Hospitalisatieverzekering
Maaltijdcheques
Ecocheques
+1
Brussels SIEM Data Engineer: Onboard & Optimize Logs
Brussels SIEM Data Engineer: Onboard & Optimize Logs

Editx • Brussel

Sur place
EUR 65 000 - 90 000
SIEM Data Engineer – Brussel-centrum
SIEM Data Engineer – Brussel-centrum

IT-Planet NV • Gent

Sur place
EUR 90 000 - 120 000
Hospitalisatieverzekering
Maaltijdcheques
Ecocheques
+1
SIEM Specialist
SIEM Specialist

Huxley • Waals-Brabant

Hybride
EUR 60 000 - 80 000
Conditions attractives selon l'ex­péri
SIEM Engineer — Splunk Platform Owner for NATO with security clearance
SIEM Engineer — Splunk Platform Owner for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Senior Splunk Engineer: Cyber Defense & Ops Platform
Senior Splunk Engineer: Cyber Defense & Ops Platform

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 105 000
Splunk Engineer
Splunk Engineer

Vector Synergy • Brussel

Sur place
EUR 85 000 - 115 000
SIEM Engineer — Splunk Platform Owner for NATO with security clearance
SIEM Engineer — Splunk Platform Owner for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 90 000 - 120 000