Splunk Engineer

Huxley

Town of Belgium (WI)

On-site

USD 120,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Huxley is seeking an experienced SIEM Data Onboarding Engineer to join a large-scale cybersecurity environment. You will lead Splunk onboarding, design scalable ingestion pipelines, and ensure high-quality log ingestion across Windows, Linux, and cloud sources.

Candidates should be proficient in SPL, CIM, and Cribl, with strong scripting skills (Python/PowerShell) and English fluency. The role collaborates with security operations and tuning of data flows for cost efficiency.

Qualifications

  • Experience onboarding complex log sources into Splunk.
  • Strong knowledge of Splunk CIM and data inputs.
  • Experience with Windows and Linux logs and cloud logs (Azure/AWS/GCP).
  • Proficient in Python, PowerShell, or similar scripting for automation.
  • Fluent English required; French desirable.

Responsibilities

  • Lead onboarding of new log and telemetry sources into Splunk.
  • Gather technical requirements from stakeholders and source system owners.
  • Design and implement scalable ingestion pipelines.
  • Configure and validate data collection mechanisms.
  • Troubleshoot ingestion, parsing, and normalization issues.
  • Map log sources to the Splunk CIM.
  • Collaborate with security operations and detection engineering teams.
  • Perform data quality assessments and resolve data integrity issues.
  • Optimise data flows for scalability, performance, and cost efficiency.
  • Support onboarding of cloud, infrastructure, application, network, and security data sources.
  • Create and maintain onboarding documentation and procedures.
  • Contribute to SIEM onboarding standards and continuous improvement initiatives.

Skills

Splunk Enterprise
Splunk Cloud
SPL
CIM
Forwarders
Data ingestion
Troubleshooting
Security monitoring

Tools

Cribl Stream

Job description

SIEM Data Onboarding Engineer (Splunk)
Project Context

For our client, we are looking for an experienced SIEM Data Onboarding Engineer to join a large-scale cybersecurity and security operations environment. The consultant will play a key role in integrating new data sources into a Splunk-based SIEM platform, ensuring high-quality log ingestion, normalization, and alignment with security monitoring and detection requirements.

The environment includes a broad range of infrastructure, cloud, network, security, and application technologies. Experience with Cribl is highly desirable, as it is used for telemetry optimisation, routing, transformation, and data management before ingestion into Splunk.

Responsibilities
  • Lead the onboarding of new log and telemetry sources into Splunk.
  • Gather technical requirements from stakeholders and source system owners.
  • Design and implement scalable ingestion pipelines.
  • Configure and validate data collection mechanisms.
  • Troubleshoot ingestion, parsing, and normalization issues.
  • Map log sources to the Splunk Common Information Model (CIM).
  • Collaborate with security operations and detection engineering teams.
  • Perform data quality assessments and resolve data integrity issues.
  • Optimise data flows for scalability, performance, and cost efficiency.
  • Support onboarding of cloud, infrastructure, application, network, and security data sources.
  • Create and maintain onboarding documentation and operational procedures.
  • Contribute to SIEM onboarding standards and continuous improvement initiatives.
Required Skills
Splunk
  • Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
  • Proven background onboarding complex log sources.
  • Experience with:
    • Universal Forwarders
    • Heavy Forwarders
    • Data Inputs
    • Index Management
    • Source Types
    • Field Extractions
    • Splunk CIM
    • SPL (Search Processing Language)
  • Strong troubleshooting and problem-solving skills.
SIEM & Security
  • Good understanding of SIEM architecture and security monitoring.
  • Experience with logs from:
    • Windows and Linux environments
    • Network devices
    • Security appliances
    • Azure, AWS and/or GCP
    • Enterprise applications and middleware
  • Knowledge of event correlation and log management principles.
Data Engineering & Integration
  • Experience with ingestion architectures and log transport technologies.
  • Understanding of JSON, XML, Syslog, REST APIs, and event streaming.
  • Scripting and automation experience with Python, PowerShell, or similar.
Preferred Skills
Cribl
  • Hands-on experience with Cribl Stream.
  • Experience creating pipelines, transformations, routing rules, and filters.
  • Knowledge of telemetry optimisation and observability practices.
  • Experience reducing SIEM ingestion costs through data engineering strategies.
Profile
  • Strong stakeholder management skills.
  • Analytical and detail-oriented mindset.
  • Able to work independently.
  • Excellent communication skills.
  • Comfortable working with security, infrastructure, and application teams.
  • Fluent English required.
  • French prefered desirable.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr SIEM Data Engineer
Sr SIEM Data Engineer

Shain Associates • Quincy (MA)

Hybrid
USD 140,000 - 190,000
Senior Splunk SIEM Data Onboarding Engineer
Senior Splunk SIEM Data Onboarding Engineer

Huxley • Town of Belgium (WI)

On-site
USD 120,000 - 160,000
Splunk Architect
Splunk Architect

Tata Consultancy Services • Charlotte (NC)

On-site
USD 95,000 - 120,000
Senior Cribl Engineer / Security Data Engineer
Senior Cribl Engineer / Security Data Engineer

TSG Risk Management • Charlotte (NC)

On-site
USD 120,000 - 160,000
Cribl Engineer Expert
Cribl Engineer Expert

DAn Solutions • Washington

On-site
USD 120,000 - 150,000
Cribl Engineer Expert
Cribl Engineer Expert

Scalis LLC • Reston (VA)

On-site
USD 180,000 - 240,000
Cribl Engineer
Cribl Engineer

Disruptive Solutions, LLC • Washington, Northern (KY)

On-site
USD 110,000 - 170,000
Cribl Engineer: Data Pipelines & SIEM Specialist
Cribl Engineer: Data Pipelines & SIEM Specialist

ENS Solutions, LLC • Reston (VA)

On-site
USD 110,000 - 150,000
Free Platinum Medical/Dental/Vision
401k from Day 1
PTO + 11 paid holidays
+3
Senior Cribl Engineer / Security Data Engineer
Senior Cribl Engineer / Security Data Engineer

your Jared • Charlotte (NC), Northern (KY)

Hybrid
USD 130,000 - 160,000
Splunk Architect: Enterprise SIEM & Analytics Lead
Splunk Architect: Enterprise SIEM & Analytics Lead

Fuse Engineering • Fort Meade (MD)

On-site
USD 120,000 - 150,000