WLG

Security Data Engineer — SIEM Operations and Automation for NATO with security clearance

WLG Mons, Wallonia, Belgium

Financial Services · 2-10 employees

6 h ago
Senior (5-10 yrs) Full-time Belgium
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will act as the subject matter expert for a large-scale Splunk monitoring estate, overseeing log collection, detection tooling, and system architecture. Additionally, you will lead technical projects, manage performance targets, and provide executive reporting to stakeholders.

What they look for

Splunk Linux Administration Bash Python Ansible Log Collection Security Monitoring Network Security Distributed Architectures Troubleshooting Regular Expressions Technical Writing Enterprise Security SOAR UBA Git

Requirements

The role requires extensive hands-on experience with Splunk administration, distributed system design, and strong Linux troubleshooting skills. Candidates must also possess proficiency in scripting languages like Python or Bash and have a solid foundation in network and communication security.

Full description

A multinational defence organisation runs its security monitoring on a large,distributed Splunk estate, and is looking for the engineer who will own it. This is the seniortechnical voice on log collection and detection tooling for a cyber security data team, not aticket-queue role.

What you would be doing

  • Acting as the subject matter expert for the monitoring platform and everything that feedsit — advising other teams, sizing changes and taking the technical lead on related projects.
  • Designing, deploying and maintaining distributed architectures, and keeping the whole estateinstalled, configured and behaving.
  • Watching every component, spotting abnormal behaviour early in system, security andapplication logs, and taking the technical and the non-technical action needed to clear it.
  • Keeping the service inside the performance targets agreed with the customers it protects.
  • Integrating external tooling, and proposing the improvements that keep the environmentcurrent instead of merely alive.
  • Writing up the business case and the implementation plan for change boards, then deliveringthe approved change with the other teams involved.
  • Producing documentation, procedures and design notes, plus technical and executive reportingand the occasional briefing to a senior audience.
  • Taking a turn on call, so that monitoring stays available when something breaks out ofhours.

What you would bring

  • Hands-on time administering Splunk in a large enterprise — deployment, installation,configuration and maintenance — and real experience of distributed designs.
  • Expert-level background in log collection and security monitoring management, with theanalytical habit of reading logs to diagnose rather than to confirm.
  • Strong Linux administration and troubleshooting, and comfort with regular expressions.
  • Scripting to take the repetition out of the work: Bash, Python or Ansible.
  • A solid grounding in computer and communication security, networking, and where modernoperating systems and applications tend to be weak.
  • Clear technical writing and the ability to explain a complicated problem to people who donot share your background.
  • Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection,and an industry certification such as CISSP, CISM or a GIAC.

Extensions are offered where the work goes well. Applications are reviewed as theyarrive.