Back to all jobs
Visible on IKONS todayNewPopular

Data Engineer

BrusselsOn site40 hours/week<3months

An organization is looking for an experienced Data Onboarding Engineer to support the integration of new data sources into a Splunk-based Security Information and Event Management (SIEM) platform. The consultant will work closely with security operations, infrastructure, application, and business teams to ensure that log sources are efficiently onboarded, correctly normalized, and aligned with security monitoring requirements.

Experience with a data optimization tool like Cribl is highly desired for optimizing, routing, transforming, and managing telemetry data to the SIEM platform.

What you do

  • Leading and executing the onboarding of new log and telemetry sources into the SIEM platform
  • Gathering technical requirements from stakeholders and source system owners
  • Designing and implementing data ingestion pipelines
  • Configuring, validating, and troubleshooting data collection mechanisms
  • Ensuring logs are correctly parsed, normalized, and, where applicable, mapped to the Common Information Model (CIM)
  • Developing and maintaining onboarding documentation, data flow diagrams, and operational procedures
  • Collaborating with cybersecurity teams to understand use cases and ensure onboarding meets detection and monitoring requirements
  • Performing data quality assessments and resolving data ingestion issues
  • Optimizing data flows to improve performance, scalability
  • Supporting the onboarding of data sources from cloud, infrastructure, networks, security
  • Contributing to the continuous improvement of the SIEM data onboarding framework and associated standards

What they ask

  • Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud
  • Experience with onboarding and managing diverse log sources
  • Knowledge of Universal Forwarders, Heavy Forwarders, Data Inputs, index management, source types, field extractions, Splunk CIM, and Search Processing Language (SPL)
  • Experience with troubleshooting data ingestion and parsing issues
  • Good knowledge of SIEM concepts and security monitoring
  • Knowledge of security logs from operating systems (Windows/Linux), network devices, security appliances, cloud platforms (Azure, AWS, GCP), applications
  • Understanding of log management and event correlation principles
  • Experience with log transport technologies and data ingestion architectures
  • Knowledge of JSON, XML, Syslog, REST APIs, and event streaming concepts
  • Experience with scripting or automation via Python, PowerShell, or similar technologies

Desired qualifications.

  • Hands-on experience with Cribl Stream and/or other Cribl products
  • Experience with creating pipelines, routing rules, transformations, and filtering logic
  • Knowledge of observability and telemetry optimization practices
  • Experience with reducing SIEM ingestion costs through data engineering techniques
  • Knowledge of SOC operations and detection engineering
  • Experience within large-scale enterprise environments
  • Knowledge of cloud-native logging and monitoring services

Profile

  • Strong analytical and troubleshooting skills
  • Ability to work independently with limited guidance
  • Excellent stakeholder management and communication skills
  • Comfortable collaborating with infrastructure, security, and application teams
  • Strongly focused on documentation and attention to detail
  • Fluent English; Dutch and/or French are a plus

How to apply

View the full assignment text and application details once your tailored application is ready.

Order a tailored application to view the full assignment and application details.

More context, less searching.

You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.