SIEM Data Onboarding Engineer (Splunk)
Project Context
For our client, we are looking for an experienced SIEM Data Onboarding Engineer to join a large-scale cybersecurity and security operations environment. The consultant will play a key role in integrating new data sources into a Splunk-based SIEM platform, ensuring high-quality log ingestion, normalization, and alignment with security monitoring and detection requirements.
The environment includes a broad range of infrastructure, cloud, network, security, and application technologies. Experience with Cribl is highly desirable, as it is used for telemetry optimisation, routing, transformation, and data management before ingestion into Splunk.
Responsibilities
- Lead the onboarding of new log and telemetry sources into Splunk.
- Gather technical requirements from stakeholders and source system owners.
- Design and implement scalable ingestion pipelines.
- Configure and validate data collection mechanisms.
- Troubleshoot ingestion, parsing, and normalization issues.
- Map log sources to the Splunk Common Information Model (CIM).
- Collaborate with security operations and detection engineering teams.
- Perform data quality assessments and resolve data integrity issues.
- Optimise data flows for scalability, performance, and cost efficiency.
- Support onboarding of cloud, infrastructure, application, network, and security data sources.
- Create and maintain onboarding documentation and operational procedures.
- Contribute to SIEM onboarding standards and continuous improvement initiatives.
Required Skills
Splunk
- Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
- Proven background onboarding complex log sources.
- Experience with:
- Universal Forwarders
- Heavy Forwarders
- Data Inputs
- Index Management
- Source Types
- Field Extractions
- Splunk CIM
- SPL (Search Processing Language)
- Strong troubleshooting and problem-solving skills.
SIEM & Security
- Good understanding of SIEM architecture and security monitoring.
- Experience with logs from:
- Windows and Linux environments
- Network devices
- Security appliances
- Azure, AWS and/or GCP
- Enterprise applications and middleware
- Knowledge of event correlation and log management principles.
Data Engineering & Integration
- Experience with ingestion architectures and log transport technologies.
- Understanding of JSON, XML, Syslog, REST APIs, and event streaming.
- Scripting and automation experience with Python, PowerShell, or similar.
Preferred Skills
Cribl
- Hands-on experience with Cribl Stream.
- Experience creating pipelines, transformations, routing rules, and filters.
- Knowledge of telemetry optimisation and observability practices.
- Experience reducing SIEM ingestion costs through data engineering strategies.
Profile
- Strong stakeholder management skills.
- Analytical and detail-oriented mindset.
- Able to work independently.
- Excellent communication skills.
- Comfortable working with security, infrastructure, and application teams.
- Fluent English required.
- French prefered desirable.