SIEM Data Onboarding Engineer (Splunk)
SIEM Data Onboarding Engineer (Splunk)
For a client we are seeking a SIEM Data Onboarding Engineer (Splunk) to join our team on a full-time basis. This is a long-term position with an initial contract until 31/12, with the possibility of extension. The role requires working on-site in Brussels North for two days a week.
Role Overview
We are looking for an experienced SIEM Data Onboarding Engineer to support the integration of new data sources into our Splunk-based Security Information and Event Management (SIEM) platform. The consultant will collaborate closely with security operations, infrastructure, application, and business teams to ensure efficient onboarding of log sources, appropriate normalization, and alignment with security monitoring requirements. Experience with Cribl is highly desirable, as it is used to optimize, route, transform, and manage telemetry data flows into Splunk.
Key Responsibilities
- Lead and execute the onboarding of new log and telemetry sources into Splunk.
- Gather technical requirements from stakeholders and source system owners.
- Design and implement data ingestion pipelines.
- Configure, validate, and troubleshoot data collection mechanisms.
- Ensure logs are properly parsed, normalized, and mapped to Splunk Common Information Model (CIM) where applicable.
- Develop and maintain onboarding documentation, data flow diagrams, and operational procedures.
- Work with cybersecurity teams to understand use cases and ensure onboarding supports detection and monitoring requirements.
- Perform data quality assessments and resolve ingestion issues.
- Optimize data flows to improve performance, scalability, and cost efficiency.
- Support onboarding of cloud, infrastructure, network, security, and application data sources.
- Contribute to continuous improvement of the SIEM data onboarding framework and standards.
Required Skills & Experience
- Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
- Experience onboarding and managing diverse log sources.
- Knowledge of Universal Forwarders, Heavy Forwarders, Data Inputs, Index management, Source types, Field extractions, Splunk CIM, and Search Processing Language (SPL).
- Experience troubleshooting data ingestion and parsing issues.
SIEM & Security
- Good understanding of SIEM concepts and security monitoring.
- Familiarity with security logs from operating systems (Windows/Linux), network devices, security appliances, cloud platforms (Azure, AWS, GCP), applications, and middleware.
- Understanding of log management and event correlation principles.
Data Engineering & Integration
- Experience with log transport technologies and ingestion architectures.
- Understanding of JSON, XML, Syslog, REST APIs, and event streaming concepts.
- Experience with scripting or automation using Python, PowerShell, or similar technologies.
Preferred Qualifications
- Hands-on experience with Cribl Stream and/or related Cribl products.
- Experience creating pipelines, routing rules, transformations, and filtering logic.
- Knowledge of observability and telemetry optimization practices.
- Experience reducing SIEM ingestion costs through data engineering techniques.
Additional Desirable Skills
- Understanding of SOC operations and detection engineering.
- Experience working in enterprise-scale environments.
- Knowledge of cloud-native logging and monitoring services.
Profile
- Strong analytical and troubleshooting skills.
- Ability to work independently with limited supervision.
- Excellent stakeholder management and communication skills.
- Comfortable working across infrastructure, security, and application teams.
- Documentation-oriented with strong attention to detail.
- Fluent in English; Dutch and/or French are a plus.