SIEM Engineer - Splunk Platform Owner for NATO with security clearance
WLG
Bergen, Belgium
17 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Bash Shell
Cyber Security
Distributed Systems
Python (Programming Language)
Linux System Administration
Regular Expressions
Ansible
Security Information and Event Management
Systems Integration
Scripting
Git
Splunk
Job description
A multinational defence organisation runs its security monitoring on a large, distributed Splunk estate, and is looking for the engineer who will own it. This is the senior technical voice on log collection and detection tooling for a cyber security data team, not a ticket-queue role.
What you would be doing
- Acting as the subject matter expert for the monitoring platform and everything that feeds it - advising other teams, sizing changes and taking the technical lead on related projects.
- Designing, deploying and maintaining distributed architectures, and keeping the whole estate installed, configured and behaving.
- Watching every component, spotting abnormal behaviour early in system, security and application logs, and taking the technical and the non-technical action needed to clear it.
- Keeping the service inside the performance targets agreed with the customers it protects.
- Integrating external tooling, and proposing the improvements that keep the environment current instead of merely alive.
- Writing up the business case and the implementation plan for change boards, then delivering the approved change with the other teams involved.
- Producing documentation, procedures and design notes, plus technical and executive reporting and the occasional briefing to a senior audience.
- Taking a turn on call, so that monitoring stays available when something breaks out of hours.
Requirements
- Hands-on time administering Splunk in a large enterprise - deployment, installation, configuration and maintenance - and real experience of distributed designs.
- Expert-level background in log collection and security monitoring management, with the analytical habit of reading logs to diagnose rather than to confirm.
- Strong Linux administration and troubleshooting, and comfort with regular expressions.
- Scripting to take the repetition out of the work: Bash, Python or Ansible.
- A solid grounding in computer and communication security, networking, and where modern operating systems and applications tend to be weak.
- Clear technical writing and the ability to explain a complicated problem to people who do not share your background.
- Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection, and an industry certification such as CISSP, CISM or a GIAC.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IK
Igor Khokhriakov
about 2 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
11 months ago
CH
Chris Heilmann
Dev Digest 121 - AI goes offline
over 2 years ago