Siem Data Engineer | Cribl | Full Remote (Spain)
Role details
Job location
Tech stack
Job description
OverviewSenior Cribl / SIEM Engineer| Full Remote (Spain)Capitole Consulting is growing, and we are seeking a Senior Cribl / SIEM Engineer to join an international cybersecurity project. You will design and evolve next-generation SIEM and Log Stream Processing platforms within Car IT and OT (Operational Technology) environments. If you are passionate about Cribl, Splunk, SIEM engineering, data pipelines and cybersecurity, we would like to meet you.ResponsibilitiesDesign, implementing and optimizing log processing pipelines using Cribl.Connect new security log sources to enterprise SIEM platforms.Develop parsers, transformations and normalization rules for heterogeneous log sources.Define security data models and detection use cases.Design and document SIEM use cases to continuously improve threat detection capabilities.Perform SIEM consulting activities, identify new security requirements and propose technical solutions.Optimize log ingestion, routing and enrichment processes.Support the evolution of enterprise Log Stream Processing platforms.Implement privacy controls including data masking and anonymization before data ingestion.Participate in Proof of Concepts (PoCs) for new cybersecurity standards and technologies (OCSF, new integrations, etc.).Support incident resolution related to SIEM, Cribl and automation platforms.Automate operational tasks using Infrastructure as Code and CI/CD practices.Collaborate closely with SOC, Detection Engineering, Infrastructure and Cloud teams.What are we looking for?3+ years of experience working with Cribl or Log Stream Processing platforms.Strong experience with Splunk Enterprise / Splunk ES or Elastic SIEM.Experience designing and maintaining data pipelines for security logs.Experience creating parsers and data normalization rules.Strong understanding of common log formats.Excellent knowledge of Regular Expressions (Regex).Knowledge of Security Incident Response processes and Playbooks.Linux, UNIX and Windows administration knowledge.Experience with one or more cloud platforms: AWS.Experience with Python, Bash / Shell.Git / GitHub.Strong analytical and problem-solving skills.Ability to communicate with both technical and business stakeholders.Nice to haveOCSF (Open Cybersecurity Schema Framework)SOAR platformsOpenStackTerraformAnsibleGitHub ActionsData Privacy / Data MaskingAutomotive or Industrial (OT) environmentsDomainsSIEM & Security: Cribl, Splunk Enterprise, Splunk ES, Elastic, Security Incident Response, Security Use Cases, PlaybooksCloud: AWSAutomation: Terraform, Ansible, GitHub, GitHub ActionsProgramming & Scripting: Python, BashInfrastructure: UNIX, Windows, OpenStackLocation100% Remote(Only from Spain)Benefits€1,200 annual individual training budget (certifications, conferences, books, courses)Private medical insurance fully covered by Capitole.Flexible working hours.Flexible remuneration plan (restaurant, transport and childcare).Continuous feedback with monthly follow-ups.Internal Tech Communities.Team Buildings every two months, Summer Party and Christmas Dinner.And above all, a fantastic team where people truly come first.If you're looking for a technically challenging cybersecurity project where you can make a real impact building the next generation of SIEM capabilities, we'd love to meet you!#CyberSecurity #SIEM #Splunk #Cribl #LogManagement #DetectionEngineering #SOC #SecurityEngineer #CloudSecurity #AWS #Azure #GCP #Python #Linux #Terraform #Ansible #RemoteJobs #Hiring #CapitoleConsultingThe employee will adhere to information security policies:Will have access to confidential information related to Capitole and the project they are working on.Must comply with the security policies and internal policies of the company and the client.#J-*****-Ljbffr
Requirements
3+ years of experience working with Cribl or Log Stream Processing platforms. Strong experience with Splunk Enterprise / Splunk ES or Elastic SIEM. Experience designing and maintaining data pipelines for security logs. Experience creating parsers and data normalization rules. Strong understanding of common log formats. Excellent knowledge of Regular Expressions (Regex). Knowledge of Security Incident Response processes and Playbooks. Linux, UNIX and Windows administration knowledge. Experience with one or more cloud platforms: AWS. Experience with Python, Bash / Shell. Git / GitHub. Strong analytical and problem-solving skills. Ability to communicate with both technical and business stakeholders.