SIEM Data Engineer (Vitoria-Gasteiz)
Role details
Job location
Tech stack
Job description
Capitole, located in Vitoria, Spain, seeks a skilled SIEM Data Engineer to join an international project for a leading German automotive client. This role involves security log analysis, log ingestion, and SIEM data modelling, collaborating with security and operations teams., * Connect security-relevant log sources to a SIEM through Log Stream Processing platforms.
- Analyse security logs and define data models.
- Create and maintain parsers to normalize log data.
- Support SIEM data ingestion and security use case definition.
- Work with security and operations teams to improve log processing solutions.
Conocimientos
SIEM tools (Splunk, Elastic / ELK) Log management Log Stream Processing (Cribl, Kafka, Logstash) Descripción del empleo
Empowering people. Unlocking innovation.
With 1,000+ professionals and over a decade of experience, we've built an environment where talent is trusted, supported and continuously challenged to grow. Our culture
- People-first culture built on trust and real proximity.
- Stable environment with turnover clearly below industry average.
- International, high-impact projects powered by modern tech stacks.
- 1,200 Euro annual training budget per employee.
- Real flexibility, not just a promise.
- Continuous feedback culture with monthly follow-ups and annual 360 reviews.
- Private health insurance, versatile compensation and Wellhub.
- Active tech communities where knowledge is shared and innovation evolves.
- A team that delivers and celebrates together.
Ready to grow with us? Take a look at this opportunity.
We are looking for a SIEM Data Engineer / SIEM & Log Management Engineer to join an international project for a leading German client in the automotive sector. The role is focused on security log analysis, log ingestion, parsing, normalization and SIEM data modelling, working closely with security and operations teams.
We are especially interested in professionals with experience in Cribl and Splunk, although similar experience with log pipelines, log management, streaming technologies or SIEM environments will also be valued, especially with tools such as Kafka, Logstash or Elastic / ELK. What will you do?
- Connect security-relevant log sources to a SIEM through Log Stream Processing platforms.
- Analyse security logs and define data models.
- Create and maintain parsers to normalize log data.
- Support SIEM data ingestion and security use case definition.
- Work with security and operations teams to improve log processing solutions.
Requirements
Ideal candidates will have 3+ years of experience with SIEM tools like Splunk, alongside experience with Cribl or similar streaming technologies. The role promises a dynamic work environment with advanced tech stacks., * 3+ years of experience with SIEM or log management tools, especially Splunk or Elastic / ELK.
- Hands-on experience with Cribl or similar Log Stream Processing tools., * 3+ years of experience with SIEM or log management tools, especially Splunk, Elastic / ELK or similar.
- Hands-on experience with Cribl or similar Log Stream Processing / log pipeline tools such as Kafka, Logstash.