SIEM Engineer — Splunk Platform Owner for NATO with security clearance

Wlgroup

Henegouwen

Sur place

EUR 90 000 - 120 000

Plein temps

Il y a 4 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

Wlgroup seeks a senior Splunk/Log Monitoring Engineer to own a large distributed Splunk estate and be the security data team's senior technical voice. This role is hands-on and not a ticket-based queue position.

You will design, deploy and maintain distributed architectures, keep the estate installed and performing, and drive improvements to stay current with evolving threats and tech. On-call duties are included.

Qualifications

  • Hands-on Splunk administration in a large enterprise: deployment, installation, configuration and maintenance.
  • Expert-level background in log collection and security monitoring management.
  • Strong Linux administration and troubleshooting, with regex proficiency.
  • Scripting to remove repetitive work: Bash, Python or Ansible.
  • Solid grounding in security, networking and OS weaknesses.
  • Clear technical writing; able to explain complex problems to non‑experts.
  • Nice to have: CISSP, CISM or GIAC certifications and related security tools.

Responsabilités

  • Acting as the subject matter expert for the monitoring platform and everything that feeds it — advising other teams, sizing changes and taking the technical lead on related projects.
  • Designing, deploying and maintaining distributed architectures, and keeping the whole estate installed, configured and behaving.
  • Watching every component, spotting abnormal behaviour early in system, security and application logs, and taking the technical and the non-technical action needed to clear it.
  • Keeping the service inside the performance targets agreed with the customers it protects.
  • Integrating external tooling, and proposing the improvements that keep the environment current instead of merely alive.
  • Writing up the business case and the implementation plan for change boards, then delivering the approved change with the other teams involved.
  • Producing documentation, procedures and design notes, plus technical and executive reporting and the occasional briefing to a senior audience.
  • Taking a turn on call, so that monitoring stays available when something breaks out of hours.

Connaissances

Splunk administration
Security monitoring
Linux administration
Scripting (Bash/Python/Ansible)
Technical writing
Log analysis
On-call experience

Formation

CISSP/CISM/GIAC certification

Outils

SOAR
UBA
Custom parsers
Git
Cloud log collection

Description du poste

A multinational defence organisation runs its security monitoring on a large, distributed Splunk estate, and is looking for the engineer who will own it. This is the senior technical voice on log collection and detection tooling for a cyber security data team, not a ticket-queue role.

What you would be doing
  • Acting as the subject matter expert for the monitoring platform and everything that feeds it — advising other teams, sizing changes and taking the technical lead on related projects.
  • Designing, deploying and maintaining distributed architectures, and keeping the whole estate installed, configured and behaving.
  • Watching every component, spotting abnormal behaviour early in system, security and application logs, and taking the technical and the non-technical action needed to clear it.
  • Keeping the service inside the performance targets agreed with the customers it protects.
  • Integrating external tooling, and proposing the improvements that keep the environment current instead of merely alive.
  • Writing up the business case and the implementation plan for change boards, then delivering the approved change with the other teams involved.
  • Producing documentation, procedures and design notes, plus technical and executive reporting and the occasional briefing to a senior audience.
  • Taking a turn on call, so that monitoring stays available when something breaks out of hours.
What you would bring
  • Hands-on time administering Splunk in a large enterprise — deployment, installation, configuration and maintenance — and real experience of distributed designs.
  • Expert-level background in log collection and security monitoring management, with the analytical habit of reading logs to diagnose rather than to confirm.
  • Strong Linux administration and troubleshooting, and comfort with regular expressions.
  • Scripting to take the repetition out of the work: Bash, Python or Ansible.
  • A solid grounding in computer and communication security, networking, and where modern operating systems and applications tend to be weak.
  • Clear technical writing and the ability to explain a complicated problem to people who do not share your background.
  • Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection, and an industry certification such as CISSP, CISM or a GIAC.

Extensions are offered where the work goes well. Applications are reviewed as they arrive.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Data Engineer — SIEM Operations and Automation for NATO with security clearance
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance
Splunk Specialist — Log Collection and Detection Support for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Cyber Security Defender (SIEM & Splunk)
Cyber Security Defender (SIEM & Splunk)

Global Roles • Henegouwen

Hybride
EUR 70 000 - 100 000
Senior Splunk Engineer — Cyber Defence Monitoring for NATO with security clearance
Senior Splunk Engineer — Cyber Defence Monitoring for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Senior Cyber Security Engineer — Splunk Development and Operational Support for NATO with security clearance
Senior Cyber Security Engineer — Splunk Development and Operational Support for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 105 000
Splunk Developer and Platform Owner — Security Operations for NATO with security clearance
Splunk Developer and Platform Owner — Security Operations for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 72 000 - 102 000
C005335 Splunk Engineer (NS) - MON 21 Sep
C005335 Splunk Engineer (NS) - MON 21 Sep

EMW • Henegouwen

Hybride
EUR 75 000 - 105 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
On-Site Splunk SIEM Engineer – NATO Secret Clearance
On-Site Splunk SIEM Engineer – NATO Secret Clearance

EMW • Henegouwen

Hybride
EUR 75 000 - 105 000