SIEM Data Engineer
Role details
Job location
Tech stack
Job description
security log analysis, log ingestion, parsing, normalization and SIEM data modelling , working closely with security and operations teams.We are especially looking for someone with experience in
Requirements
Cribl and Splunk , although similar experience with log pipeline, log management or SIEM environments will also be valued. What will you do?Connect security-relevant log sources to a SIEM through Log Stream Processing platforms.Analyse security logs and define data models.Create and maintain parsers to normalize log data.Support SIEM data ingestion and security use case definition.Work with security and operations teams to improve log processing solutions. What are we looking for?3+ years of experience with SIEM tools, especially Splunk or Elastic.Hands-on experience with Cribl or similar Log Stream Processing tools.Strong knowledge of log analysis, parsing, Regex and data normalization.Experience with Linux/UNIX/Windows environments and network technologies.Scripting experience with Python, Bash/Shell or JavaScript.Knowledge of cloud or container technologies such as AWS, Azure, GCP, Kubernetes or OpenStack.Understanding of Security Incident Response or security monitoring processes.Excellent English level, both written and spoken.