Siem Data Engineer | Cribl | Full Remote (Spain)

Capitole
Badajoz, Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
€ 14K

Job location

Remote
Badajoz, Spain

Tech stack

Microsoft Windows
Amazon Web Services (AWS)
Bash
Unix
Cloud Computing
Computer Security
Continuous Integration
Data Masking
Data Normalization
Linux
Github
Intrusion Detection and Prevention
Python
Automation of Marketing
OpenStack
Parsing
Regular Expressions
Ansible
Security Log
Security Information and Event Management
Privacy Controls
Scripting (Bash/Python/Go/Ruby)
Data Ingestion
Terraform
Stream Processing
Splunk
Data Pipelines

Job description

OverviewSenior Cribl / SIEM Engineer| Full Remote (Spain)Capitole Consulting is growing, and we are seeking a Senior Cribl / SIEM Engineer to join an international cybersecurity project. You will design and evolve next-generation SIEM and Log Stream Processing platforms within Car IT and OT (Operational Technology) environments. If you are passionate about Cribl, Splunk, SIEM engineering, data pipelines and cybersecurity, we would like to meet you.ResponsibilitiesDesign, implementing and optimizing log processing pipelines using Cribl.Connect new security log sources to enterprise SIEM platforms.Develop parsers, transformations and normalization rules for heterogeneous log sources.Define security data models and detection use cases.Design and document SIEM use cases to continuously improve threat detection capabilities.Perform SIEM consulting activities, identify new security requirements and propose technical solutions.Optimize log ingestion, routing and enrichment processes.Support the evolution of enterprise Log Stream Processing platforms.Implement privacy controls including data masking and anonymization before data ingestion.Participate in Proof of Concepts (PoCs) for new cybersecurity standards and technologies (OCSF, new integrations, etc.).Support incident resolution related to SIEM, Cribl and automation platforms.Automate operational tasks using Infrastructure as Code and CI/CD practices.Collaborate closely with SOC, Detection Engineering, Infrastructure and Cloud teams.What are we looking for?3+ years of experience working with Cribl or Log Stream Processing platforms.Strong experience with Splunk Enterprise / Splunk ES or Elastic SIEM.Experience designing and maintaining data pipelines for security logs.Experience creating parsers and data normalization rules.Strong understanding of common log formats.Excellent knowledge of Regular Expressions (Regex).Knowledge of Security Incident Response processes and Playbooks.Linux, UNIX and Windows administration knowledge.Experience with one or more cloud platforms: AWS.Experience with Python, Bash / Shell.Git / GitHub.Strong analytical and problem-solving skills.Ability to communicate with both technical and business stakeholders.Nice to haveOCSF (Open Cybersecurity Schema Framework)SOAR platformsOpenStackTerraformAnsibleGitHub ActionsData Privacy / Data MaskingAutomotive or Industrial (OT) environmentsDomainsSIEM & Security: Cribl, Splunk Enterprise, Splunk ES, Elastic, Security Incident Response, Security Use Cases, PlaybooksCloud: AWSAutomation: Terraform, Ansible, GitHub, GitHub ActionsProgramming & Scripting: Python, BashInfrastructure: UNIX, Windows, OpenStackLocation100% Remote(Only from Spain)Benefits€1,200 annual individual training budget (certifications, conferences, books, courses)Private medical insurance fully covered by Capitole.Flexible working hours.Flexible remuneration plan (restaurant, transport and childcare).Continuous feedback with monthly follow-ups.Internal Tech Communities.Team Buildings every two months, Summer Party and Christmas Dinner.And above all, a fantastic team where people truly come first.If you're looking for a technically challenging cybersecurity project where you can make a real impact building the next generation of SIEM capabilities, we'd love to meet you!#CyberSecurity #SIEM #Splunk #Cribl #LogManagement #DetectionEngineering #SOC #SecurityEngineer #CloudSecurity #AWS #Azure #GCP #Python #Linux #Terraform #Ansible #RemoteJobs #Hiring #CapitoleConsultingThe employee will adhere to information security policies:Will have access to confidential information related to Capitole and the project they are working on.Must comply with the security policies and internal policies of the company and the client.#J-*****-Ljbffr

Requirements

3+ years of experience working with Cribl or Log Stream Processing platforms. Strong experience with Splunk Enterprise / Splunk ES or Elastic SIEM. Experience designing and maintaining data pipelines for security logs. Experience creating parsers and data normalization rules. Strong understanding of common log formats. Excellent knowledge of Regular Expressions (Regex). Knowledge of Security Incident Response processes and Playbooks. Linux, UNIX and Windows administration knowledge. Experience with one or more cloud platforms: AWS. Experience with Python, Bash / Shell. Git / GitHub. Strong analytical and problem-solving skills. Ability to communicate with both technical and business stakeholders.

Apply for this position