SIEM Engineer — Splunk Platform Owner for NATO with security clearance

WLG

Henegouwen

Sur place

EUR 90 000 - 120 000

Plein temps

Il y a 7 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

WLG in Belgium is seeking a senior engineer to own and evolve a large, distributed Splunk estate for security monitoring. You will act as the technical voice for log collection, detection tooling and related projects, guiding other teams and driving architecture decisions.

You will design, deploy and maintain distributed architectures, keep the estate healthy, and produce technical and executive reporting. The role requires hands-on Splunk work, strong Linux skills, scripting ability, and the

Qualifications

  • Hands-on Splunk administration in a large enterprise.
  • Expert-level background in log collection and security monitoring.
  • Strong Linux administration and troubleshooting.
  • Scripting to automate work: Bash, Python or Ansible.
  • Solid grounding in computer and communication security and networking.
  • Clear technical writing and ability to explain complex problems to non-experts.
  • Nice to have: CISSP, CISM or GIAC, SOAR and UBA capabilities.

Responsabilités

  • Act as subject matter expert for the monitoring platform and related feeds.
  • Design, deploy and maintain distributed architectures and keep the estate healthy.
  • Spot anomalies in logs and take appropriate technical and non-technical actions.
  • Keep services within performance targets defined with customers.
  • Integrate external tooling and propose improvements to stay current.
  • Draft business cases and implementation plans for changes and deliver approved changes.
  • Produce documentation, procedures and design notes, plus executive reporting.
  • Take on-call shifts to ensure monitoring availability after hours.

Connaissances

Splunk administration
Log collection
Security monitoring
Linux
Regex scripting
Bash
Python
Ansible
Networking basics
Technical writing
Certs (CISSP/CISM/GIAC)

Outils

Splunk
Linux
Ansible
Python
Bash
Regex
Git

Description du poste

A multinational defence organisation runs its security monitoring on a large, distributed Splunk estate, and is looking for the engineer who will own it. This is the senior technical voice on log collection and detection tooling for a cyber security data team, not a ticket-queue role.

What You Would Be Doing
  • Acting as the subject matter expert for the monitoring platform and everything that feeds it - advising other teams, sizing changes and taking the technical lead on related projects.
  • Designing, deploying and maintaining distributed architectures, and keeping the whole estate installed, configured and behaving.
  • Watching every component, spotting abnormal behaviour early in system, security and application logs, and taking the technical and the non-technical action needed to clear it.
  • Keeping the service inside the performance targets agreed with the customers it protects.
  • Integrating external tooling, and proposing the improvements that keep the environment current instead of merely alive.
  • Writing up the business case and the implementation plan for change boards, then delivering the approved change with the other teams involved.
  • Producing documentation, procedures and design notes, plus technical and executive reporting and the occasional briefing to a senior audience.
  • Taking a turn on call, so that monitoring stays available when something breaks out of hours.
What you would bring
  • Hands-on time administering Splunk in a large enterprise - deployment, installation, configuration and maintenance - and real experience of distributed designs.
  • Expert-level background in log collection and security monitoring management, with the analytical habit of reading logs to diagnose rather than to confirm.
  • Strong Linux administration and troubleshooting, and comfort with regular expressions.
  • Scripting to take the repetition out of the work: Bash, Python or Ansible.
  • A solid grounding in computer and communication security, networking, and where modern operating systems and applications tend to be weak.
  • Clear technical writing and the ability to explain a complicated problem to people who do not share your background.
  • Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection, and an industry certification such as CISSP, CISM or a GIAC.

Extensions are offered where the work goes well. Applications are reviewed as they arrive.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

SIEM Engineer — Splunk Platform Owner for NATO with security clearance
SIEM Engineer — Splunk Platform Owner for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 70 000 - 110 000
Cyber Security Defender (SIEM & Splunk)
Cyber Security Defender (SIEM & Splunk)

Global Roles • Henegouwen

Hybride
EUR 70 000 - 100 000
Senior Splunk Engineer — Cyber Defence Monitoring for NATO with security clearance
Senior Splunk Engineer — Cyber Defence Monitoring for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Senior Cyber Security Engineer — Splunk Development and Operational Support for NATO with security clearance
Senior Cyber Security Engineer — Splunk Development and Operational Support for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 105 000
Splunk Developer and Platform Owner — Security Operations for NATO with security clearance
Splunk Developer and Platform Owner — Security Operations for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 72 000 - 102 000
C005335 Splunk Engineer (NS) - MON 21 Sep
C005335 Splunk Engineer (NS) - MON 21 Sep

EMW • Henegouwen

Hybride
EUR 75 000 - 105 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000