Proximus
SIEM Data Onboarding Engineer
Freelancer Opportunity
Job title: SIEM Data Onboarding Engineer
Job location: Brussels, Belgium
Job duration: 2026-10-26 to 2027-04-30
Job weekly hours: 40 hrs./week
Job language: English (Fluent), Dutch/French is a plus.
Job description:
FORTIFIED CYBER SECURITY PLATFORMS
SIEM Data Onboarding Engineer
Splunk Security Resource
Engagement
2 resources for 6 months
Project
CSIRT for Proximus Global
Role Overview
We are seeking an experienced SIEM Data Onboarding Engineer to support the integration of new data sources into our Splunk-based Security Information and Event Management (SIEM) platform. The consultant will work closely with security operations, infrastructure, application, and business teams to ensure log sources are onboarded efficiently, normalized appropriately, and aligned with security monitoring requirements.
Experience with Cribl is highly desirable, as it is used to optimize, route, transform, and manage telemetry data flows into Splunk.
Key Responsibilities
Lead and execute onboarding of new log and telemetry sources into Splunk.
Gather technical requirements from stakeholders and source system owners.
Design and implement data ingestion pipelines.
Configure, validate, and troubleshoot data collection mechanisms.
Ensure logs are properly parsed, normalized, and mapped to the Splunk Common Information Model (CIM), where applicable.
Develop and maintain onboarding documentation, data flow diagrams, and operational procedures.
Work with cybersecurity teams to understand use cases and ensure onboarding supports detection and monitoring requirements.
Perform data quality assessments and resolve ingestion issues.
Optimize data flows to improve performance, scalability, and cost efficiency.
Support onboarding of cloud, infrastructure, network, security, and application data sources.
Contribute to continuous improvement of the SIEM data onboarding framework and standards.
Required Skills & Experience
Splunk:
Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
Experience onboarding and managing diverse log sources.
Knowledge of Universal Forwarders, Heavy Forwarders, Data Inputs, index management, source types, field extractions, Splunk CIM, and Search Processing Language (SPL).
Experience troubleshooting data ingestion and parsing issues.
SIEM & Security
Good understanding of SIEM concepts and security monitoring.
Familiarity with security logs from operating systems (Windows/Linux), network devices, security appliances, cloud platforms (Azure, AWS, GCP), applications, and middleware.
Understanding of log management and event correlation principles.
Data Engineering & Integration:
Experience with log transport technologies and ingestion architectures.
Understanding of JSON, XML, Syslog, REST APIs, and event streaming concepts.
Experience with scripting or automation using Python, PowerShell, or similar technologies.
Preferred Qualifications:
Cribl
Hands-on experience with Cribl Stream and/or related Cribl products.
Experience creating pipelines, routing rules, transformations, and filtering logic.
Knowledge of observability and telemetry optimization practices.
Experience reducing SIEM ingestion costs through data engineering techniques.
Additional Desire Skills:
Understanding of SOC operations and detection engineering.
Experience working in enterprise-scale environments.
Knowledge of cloud-native logging and monitoring services.
Profile:
Strong analytical and troubleshooting skills.
Ability to work independently with limited supervision.
Excellent stakeholder management and communication skills.
Comfortable working across infrastructure, security, and application teams.
Documentation-oriented with strong attention to detail.
Ideal Service Deliverer:
The ideal service deliverer has extensive experience onboarding complex data sources into Splunk environments and can independently drive integration activities from requirements gathering through production deployment. Experience with Cribl and large-scale SIEM environments will be considered a significant advantage.
Apply now and start your journey with Team Possible! We want to get to know you.
After your application, we will verify your profile and get back to you within 3
working days.
If you’re successful, you can expect the following steps:
An initial conversation with our recruiter - Swati Kumari
Interview with the Hiring Manager and the team.
Final decision
About Proximus
We are Team Possible turning tech into opportunities.
We are driven by four core pillars: "I care," "I make a difference," "I radically simplify," and "I embrace the future". This means you'll join a team that genuinely cares for customers and colleagues, is empowered to make a real impact, strives to radically simplify complex challenges, and is always looking ahead to embrace the future of technology. We believe in an inclusive and safe environment where everyone can thrive, offering extensive career development resources, including access to over 5,000 training modules and a minimum of 5 days of training per year, to help you continuously learn, grow, and tackle bold challenges with us.