SIEM Engineer — Splunk Platform Owner for NATO with security clearance
WLG Mons, Wallonia, Belgium
Financial Services · 2-10 employees
About the role
The SIEM Engineer will act as the subject matter expert for the Splunk monitoring platform, overseeing distributed architectures and log collection. They are responsible for maintaining system performance, integrating new tools, and delivering technical projects while providing executive reporting.
What they look for
Requirements
Candidates must have extensive hands-on experience with Splunk administration in large enterprise environments and strong Linux troubleshooting skills. Proficiency in scripting languages like Bash or Python and a solid understanding of network and communication security are required.
Full description
A multinational defence organisation runs its security monitoring on a large,distributed Splunk estate, and is looking for the engineer who will own it. This is the seniortechnical voice on log collection and detection tooling for a cyber security data team, not aticket-queue role.
What you would be doing
- Acting as the subject matter expert for the monitoring platform and everything that feedsit — advising other teams, sizing changes and taking the technical lead on related projects.
- Designing, deploying and maintaining distributed architectures, and keeping the whole estateinstalled, configured and behaving.
- Watching every component, spotting abnormal behaviour early in system, security andapplication logs, and taking the technical and the non-technical action needed to clear it.
- Keeping the service inside the performance targets agreed with the customers it protects.
- Integrating external tooling, and proposing the improvements that keep the environmentcurrent instead of merely alive.
- Writing up the business case and the implementation plan for change boards, then deliveringthe approved change with the other teams involved.
- Producing documentation, procedures and design notes, plus technical and executive reportingand the occasional briefing to a senior audience.
- Taking a turn on call, so that monitoring stays available when something breaks out ofhours.
What you would bring
- Hands-on time administering Splunk in a large enterprise — deployment, installation,configuration and maintenance — and real experience of distributed designs.
- Expert-level background in log collection and security monitoring management, with theanalytical habit of reading logs to diagnose rather than to confirm.
- Strong Linux administration and troubleshooting, and comfort with regular expressions.
- Scripting to take the repetition out of the work: Bash, Python or Ansible.
- A solid grounding in computer and communication security, networking, and where modernoperating systems and applications tend to be weak.
- Clear technical writing and the ability to explain a complicated problem to people who donot share your background.
- Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection,and an industry certification such as CISSP, CISM or a GIAC.
Extensions are offered where the work goes well. Applications are reviewed as theyarrive.