Splunk Engineer

Huxley
Brussel, Belgium
11 days ago
Apply on www.huxley.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, French
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Information Engineering Data Integrity Middleware Information Model Networking Hardware JSON Python (Programming Language)
+13 more
Linux System Administration Parsing Windows PowerShell Security Information and Event Management Data Streaming Syslog Extensible Markup Language (XML) Enterprise Software Applications Data Ingestion Data Management ArcSight Event Correlation Restful APIs Splunk

Job description

For our client, we are looking for an experienced SIEM Data Onboarding Engineer to join a large-scale cybersecurity and security operations environment. The consultant will play a key role in integrating new data sources into a Splunk-based SIEM platform, ensuring high-quality log ingestion, normalization, and alignment with security monitoring and detection requirements. The environment includes a broad range of infrastructure, cloud, network, security, and application technologies. Experience with Cribl is highly desirable, as it is used for telemetry optimisation, routing, transformation, and data management before ingestion into Splunk., * Lead the onboarding of new log and telemetry sources into Splunk.

  • Gather technical requirements from stakeholders and source system owners.
  • Design and implement scalable ingestion pipelines.
  • Configure and validate data collection mechanisms.
  • Troubleshoot ingestion, parsing, and normalization issues.
  • Map log sources to the Splunk Common Information Model (CIM).
  • Collaborate with security operations and detection engineering teams.
  • Perform data quality assessments and resolve data integrity issues.
  • Optimise data flows for scalability, performance, and cost efficiency.
  • Support onboarding of cloud, infrastructure, application, network, and security data sources.
  • Create and maintain onboarding documentation and operational procedures.
  • Contribute to SIEM onboarding standards and continuous improvement initiatives.

Requirements

  • Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
  • Proven background onboarding complex log sources.
  • Experience with:
  • Universal Forwarders
  • Heavy Forwarders
  • Data Inputs
  • Index Management
  • Source Types
  • Field Extractions
  • Splunk CIM
  • SPL (Search Processing Language)
  • Strong troubleshooting and problem-solving skills.

SIEM & Security

  • Good understanding of SIEM architecture and security monitoring.
  • Experience with logs from:
  • Windows and Linux environments
  • Network devices
  • Security appliances
  • Azure, AWS and/or GCP
  • Enterprise applications and middleware
  • Knowledge of event correlation and log management principles.

Data Engineering & Integration

  • Experience with ingestion architectures and log transport technologies.
  • Understanding of JSON, XML, Syslog, REST APIs, and event streaming.
  • Scripting and automation experience with Python, PowerShell, or similar., * Hands-on experience with Cribl Stream.
  • Experience creating pipelines, transformations, routing rules, and filters.
  • Knowledge of telemetry optimisation and observability practices.
  • Experience reducing SIEM ingestion costs through data engineering strategies., * Strong stakeholder management skills.
  • Analytical and detail-oriented mindset.
  • Able to work independently.
  • Excellent communication skills.
  • Comfortable working with security, infrastructure, and application teams.
  • Fluent English required.
  • French prefered desirable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.huxley.com
Prepare application

Good distractions

Loading talks and stories from around this role…