> Markdown version of [/jobs/ext/1460806-threat-detection-engineer-splunk-developer](https://www.wearedevelopers.com/jobs/ext/1460806-threat-detection-engineer-splunk-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Detection Engineer - Splunk Developer - **Company:** Innobo - **Location:** Brussel, Belgium - **Contract:** Permanent contract - **Skills:** Information Model, Intrusion Detection and Prevention, Security Information and Event Management, Splunk - **Published:** July 28, 2026 - **Apply:** https://www.careerjet.be/jobad/be9e6435abc045bc0fdfd02b0f1b9d5e05 ## About the Role * In depth experience in development and maintenance of SIEM use cases * Fluent in Splunk's search processing language (SPL) * Excellent knowledge of Splunk Enterprise and Splunk Enterprise Security * Sound knowledge about Splunk Common Information Model and log normalization using Data Models * Solid understanding of cybersecurity technologies, protocols, and applications * Excellent English communication skills (written and oral) Nice to have: * Splunk Core Certified (Advanced) Power User (crucial) * Splunk Certified Developer (nice to have) * Splunk Enterprise Certified Admin (nice to have) * Splunk Enterprise Security Certified Admin (nice to have) * Any other Security Certifications (e.g. CEH, GIAC, CISSP, OSCP …) Soft Skills: * Strong analytical skills to evaluate sophisticated multivariate problems and find a systematic approach to gain a quick resolution, often under stress * Strong problem solving, documentation, process execution, time management and organizational skills. * Ability to communicate sophisticated information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means * Fast and independent learner, with ambition to self-improve * At ease in a fast-changing environment, flexible and pragmatic, open-minded * Accurate, acting with attention to details * Client focus and delivery oriented * A team-focused mentality with ability to work & collaborate effectively in a team environment * Good leadership and communication skills, whether on the field, in the team or with management: you are a keen standout colleague and coordinate work among people from different areas or divisions. A good relationship builder with strong diplomacy skills * Ability to work autonomously ## Description * Interact with the different customers to capture and define requirements for the development and testing of the threat detection capabilities * Cooperate with log source onboarding team to assure correct log source onboarding and log mapping to data models according to Splunk standard processes * The development and tuning and continuous improvement of correlation rules * Develop and maintain dashboards, reports, and alerts * Create Splunk Knowledge Objects to address customers needs in context of using Splunk as security tool * Prepare correlation search tests, conduct tests, and document evidence from test that shows correlation search addresses scenario described in use case * Responsible for the creation of procedures, high-level/low-level documentation, implementation of processes and development of staff in relation to SIEM detection logic * Coach a team (from a technical perspective); review work outputs and provide quality assurance * Analyses and identifies areas of improvement with existing processes, procedures, and documentation * Demonstrates how to use SIEM & Enterprise Security products to both technical/non-technical personnel * Provides expert technical advice and counsel in the design, monitoring and improvement of SIEM security systems * Prioritize and coordinate backlog of threat detection requests, making sure we have a healthy balance between defect resolution and new features ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [OPC UA Updates and Trends](https://www.wearedevelopers.com/videos/1215-opc-ua-updates-and-trends) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Experience, Platform Engineering and AI powered Apps](https://www.wearedevelopers.com/videos/990-developer-experience-platform-engineering-and-ai-powered-apps) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [7 Most Popular Web Developer Jobs in Europe](https://www.wearedevelopers.com/magazine/163-7-most-popular-web-developer-jobs-in-europe) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023)