This job is closed
Applications are no longer available for this announcement. Explore current related opportunities below.
Job description
SIEM Data Onboarding Engineer (Splunk)
Project Context
For our client, we are looking for an experienced SIEM Data Onboarding Engineer to join a large-scale cybersecurity and security operations environment. The consultant will play a key role in integrating new data sources into a Splunk-based SIEM platform, ensuring high-quality log ingestion, normalization, and alignment with security monitoring and detection requirements.
The environment includes a broad range of infrastructure, cloud, network, security, and application technologies. Experience with Cribl is highly desirable, as it is used for telemetry optimisation, routing, transformation, and data management before ingestion into Splunk.
Responsibilities
Lead the onboarding of new log and telemetry sources into Splunk.
Gather technical requirements from stakeholders and source system owners.
Design and implement scalable ingestion pipelines.
Configure and validate data collection mechanisms.
Troubleshoot ingestion, parsing, and normalization issues.
Map log sources to the Splunk Common Information Model (CIM).
Collaborate with security operations and detection engineering teams.
Perform data quality assessments and resolve data integrity issues.
Optimise data flows for scalability, performance, and cost efficiency.
Support onboarding of cloud, infrastructure, application, network, and security data sources.
Create and maintain onboarding documentation and operational procedures.
Contribute to SIEM onboarding standards and continuous improvement initiatives.
Required Skills
Splunk
Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
Proven background onboarding complex log sources.
Experience with:Universal Forwarders
Heavy Forwarders
Data Inputs
Index Management
Source Types
Field Extractions
Splunk CIM
SPL (Search Processing Language)
Strong troubleshooting and problem-solving skills.
SIEM & Security
Good understanding of SIEM architecture and security monitoring.
Experience with logs from:Windows and Linux environments
Network devices
Security appliances
Azure, AWS and/or GCP
Enterprise applications and middleware
Knowledge of event correlation and log management principles.
Data Engineering & Integration
Experience with ingestion architectures and log transport technologies.
Understanding of JSON, XML, Syslog, REST APIs, and event streaming.
Scripting and automation experience with Python, PowerShell, or similar.
Preferred Skills
Cribl
Hands-on experience with Cribl Stream.
Experience creating pipelines, transformations, routing rules, and filters.
Knowledge of telemetry optimisation and observability practices.
Experience reducing SIEM ingestion costs through data engineering strategies.
Profile
Strong stakeholder management skills.
Analytical and detail-oriented mindset.
Able to work independently.
Excellent communication skills.
Comfortable working with security, infrastructure, and application teams.
Fluent English required.
French prefered desirable.
#J-18808-Ljbffr
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.