As a Splunk Engineer you will be instrumental in managing and enhancing our Splunk infrastructure. Your primary responsibilities will include:
Splunk Infrastructure Management:
- Install configure and maintain key Splunk components such as Splunk Enterprise Splunk Universal Forwarder and Splunk Heavy Forwarder.
- Monitor and optimize the performance of Splunk clusters to ensure efficient data processing and search capabilities.
- Troubleshoot and resolve any issues related to Splunk infrastructure to ensure high availability and reliability.
Data Ingestion and Parsing:
- Design and implement data ingestion strategies for various log sources.
- Develop and maintain parsing configurations to normalize and enrich incoming data for more effective analysis.
- Collaborate with application owners and IT teams to onboard new data sources.
Search and Reporting:
- Create and optimize search queries and reports to extract valuable insights from indexed data.
- Develop customized Splunk dashboards for various stakeholders highlighting key performance indicators and security metrics.
Security and Compliance:
- Implement security best practices within Splunk to protect sensitive data.
- Work with the security team to configure and monitor alerts for suspicious activities and security incidents.
- Ensure compliance with industry regulations and internal policies regarding log management and data retention.
Automation and Scripting:
- Develop automation scripts using SPL (Search Processing Language) and other scripting languages to streamline administrative tasks.
- Seek opportunities to enhance efficiency through automation in Splunk processes.
Documentation and Training:
- Maintain thorough documentation of Splunk configurations processes and troubleshooting procedures.
- Provide training and support to IT team members on Splunk best practices and usage.
Requirements
- Education: Bachelors degree in Computer Science Information Security or a related field.
- Experience:
- Proven experience as a Splunk Engineer in an enterpriselevel environment.
- Expertise in network and application security with familiarity in Palo Alto Bluecoat F5 (LTM ASM APM) and ASA VPN highly beneficial.
- Technical Skills:
- Strong knowledge of Splunk architecture components and best practices.
- Proficient in SPL and scripting languages such as Python or Bash.
- Experience in designing and implementing data ingestion strategies.
- Solid understanding of security principles as they apply to Splunk.
- Soft Skills:
- Excellent problemsolving and troubleshooting skills.
- Strong communication skills with the ability to collaborate with diverse teams.
- Proactive in identifying and mitigating security vulnerabilities and risks.
- Additional Requirements:
- Fluent in English.
- Relevant certifications are a plus.
- Candidate must be native from a NATO country; a valid NATO Secret Clearance is advantageous.
Workplace Type: Onsite working is required.
Benefits
- The position is open to two possibilities: permanent contract (CDI) or freelancers.
- The organization is flexible offering up to 50 days of remote work per year for permanent contracts with the possibility to negotiate for more.
- For freelance contracts remote work is flexible with a schedule of 1 week onsite and 3 weeks remote.