SIEM Data Engineer
Role details
Job location
Tech stack
Job description
Capitole in Marbella is seeking a SIEM Data Engineer to work on an international project in the automotive sector. The role focuses on security log analysis and involves working closely with security and operations teams., * Connect security-relevant log sources to a SIEM.
- Analyse security logs and define data models.
- Create and maintain parsers to normalize log data.
- Support SIEM data ingestion and security use case definition.
- Work with security and operations teams to improve log processing solutions.
Conocimientos
SIEM or log management tools Splunk Elastic / ELK Cribl Log Stream Processing Kafka Logstash Descripción del empleo
Empowering people. Unlocking innovation.
With 1,000+ professionals and over a decade of experience, we've built an environment where talent is trusted, supported and continuously challenged to grow. Our culture
- People-first culture built on trust and real proximity.
- Stable environment with turnover clearly below industry average.
- International, high-impact projects powered by modern tech stacks.
- 1,200 Euro annual training budget per employee.
- Real flexibility, not just a promise.
- Continuous feedback culture with monthly follow-ups and annual 360 reviews.
- Private health insurance, versatile compensation and Wellhub.
- Active tech communities where knowledge is shared and innovation evolves.
- A team that delivers and celebrates together.
Ready to grow with us? Take a look at this opportunity.
We are looking for a SIEM Data Engineer / SIEM & Log Management Engineer to join an international project for a leading German client in the automotive sector. The role is focused on security log analysis, log ingestion, parsing, normalization and SIEM data modelling, working closely with security and operations teams.
We are especially interested in professionals with experience in Cribl and Splunk, although similar experience with log pipelines, log management, streaming technologies or SIEM environments will also be valued, especially with tools such as Kafka, Logstash or Elastic / ELK. What will you do?
- Connect security-relevant log sources to a SIEM through Log Stream Processing platforms.
- Analyse security logs and define data models.
- Create and maintain parsers to normalize log data.
- Support SIEM data ingestion and security use case definition.
- Work with security and operations teams to improve log processing solutions.
Requirements
The ideal candidate will have over 3 years of experience with SIEM tools like Splunk, alongside hands-on skills with log processing tools such as Cribl and Kafka. Join us and enjoy a people-first culture with a focus on professional growth., * 3+ years of experience with SIEM or log management tools.
- Hands-on experience with Cribl and/or similar log pipeline tools., * 3+ years of experience with SIEM or log management tools, especially Splunk, Elastic / ELK or similar.
- Hands-on experience with Cribl or similar Log Stream Processing / log pipeline tools such as Kafka, Logstash.