C

Senior SIEM Data Engineer (Cybersecurity)

Capitole Spain
Remote Visa Sponsorship
Apply
AI Summary

Design and optimize large-scale SIEM architectures by integrating heterogeneous log sources, building scalable data pipelines, and developing advanced security use cases. Requires deep expertise in Cribl, SIEM platforms (Splunk/Elastic), and log processing with regex. Collaborate with cybersecurity teams to enhance detection capabilities and automate log workflows.

Key Highlights
Lead the design and optimization of modern cybersecurity platforms using Cribl and SIEM tools.
Develop scalable log pipelines, parsers, and security use cases for enterprise environments.
Collaborate with incident response teams and operations to improve detection and automation.
Key Responsibilities
Connect and integrate security log sources into SIEM platforms using Cribl.
Design parsers and normalize log data for efficient security monitoring.
Develop and optimize log processing pipelines and routing for scalable SIEM operations.
Create and document SIEM data models and security use cases for enterprise environments.
Participate in security assessments to identify detection opportunities and improve capabilities.
Collaborate with operations teams to automate log processing and optimize workflows.
Support incident response processes through high-quality log engineering.
Contribute to Proofs of Concept for new cybersecurity standards and technologies.
Technical Skills Required
Cribl SIEM Platforms (Splunk/Elastic) Log Processing & Normalization
Benefits & Perks
Flexible working hours with intensive Fridays
€1200 annual training budget
Private health insurance
Wellbeing support (fitness, wellness, mental health)
Processing of work permit for relocation to Spain with family
Tailored career path with monthly follow-ups and 360° evaluations
Nice to Have
Terraform
Ansible
GitHub Actions
SIEM architecture expertise
Security automation
OCSF
SOAR platforms
Data visualization
Kubernetes/OpenStack knowledge
Cloud platforms (AWS, Azure, GCP)

Job Description


Capitole is one of the best IT consulting companies and the place you want to be. Why?


🤝 People in the center. We believe in a different model, more human, with the employee in the center of our company

👨 💻 Interesting projects. Cutting-edge technologies. Agile methologies

😁 Happiness and low turnover rate

🎓 €1200 per year training budget

⌚ Flexible working hours

🌏 More than 900 skilled professionals, from more than 27 nationalities

🎯 Tailored career path

📆 Monthly follow-ups. 360º continuous evaluation

🩺 Private health insurance

💰 Flexible retribution program

🏋️ ♂️ Wellhub: access to fitness, wellness, and mental health support

📄 Processing of the work permit for you to come to Spain with your family

📢 Technological communities

🥳 Lots of amazing events


📍 Location: Spain (Full Remote)

🕒 Schedule: Flexible working hours + intensive Fridays

🌍 English: C1


At Capitole Consulting we continue growing and we are looking for a Senior SIEM Data Engineer to join an international cybersecurity team working on large-scale SIEM architectures, log processing and security automation.

You will help design and optimize modern cybersecurity platforms by integrating heterogeneous log sources, building scalable data pipelines and developing advanced SIEM use cases for enterprise environments.


Your responsibilities

  • Connect and integrate security log sources into SIEM platforms using Cribl.
  • Design parsers and normalize log data for efficient security monitoring.
  • Develop and optimize log processing and routing pipelines.
  • Create and document SIEM data models and security use cases.
  • Participate in security assessments to identify detection opportunities.
  • Improve SIEM detection capabilities and support continuous platform evolution.
  • Collaborate with operations teams to automate and optimize log processing.
  • Contribute to Proofs of Concept around new cybersecurity standards and technologies.
  • Support incident response processes through high-quality log engineering.


Requirements

  • Experience working with Cribl.
  • Experience with SIEM platforms (Splunk and/or Elastic).
  • Strong understanding of log ingestion, parsing and normalization.
  • Experience with Regular Expressions (Regex).
  • Knowledge of Security Incident Response and SIEM use cases.
  • Experience with scripting (Python, Bash/Shell or JavaScript).
  • Knowledge of Linux, Windows and UNIX.
  • Experience with GitHub.
  • Cloud knowledge in AWS, Azure and/or GCP.
  • Kubernetes and/or OpenStack knowledge is a plus.
  • Excellent analytical and problem-solving skills.
  • English C1.


Nice to have

  • Terraform
  • Ansible
  • GitHub Actions
  • SIEM architecture
  • Security automation
  • OCSF
  • SOAR platforms
  • Data visualization


Want to know more? Click here 🖱️ and find out!


See what people say about us 🕵️ ♀️ Glassdoor Reviews


Feel free to send us your profile, we are excited to meet you! 💙


The employee will adhere to information security policies:

-Will have access to confidential information related to Capitole and the project they are working on.

-Must comply with the security policies and internal policies of the company and the client.

-Must sign an NDA.


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Talan

Spain

Data Analytics Lead

Data Science
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

prime insights

Spain

Principal Data Scientist - Generative AI & Customer Relevance

Data Science
6d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

vistaprint

Spain

Subscribe our newsletter

New Things Will Always Update Regularly